Courseiva

PCNSE Deploy and Configure Firewalls Practice Question

An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?

⚠ Common exam trap

The trap here is assuming that a security rule allowing traffic is sufficient for outbound internet access, forgetting that source NAT is required for private IP addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security rule is missing a source NAT (SNAT) rule, so the server's private IP address is not translated and return traffic cannot find its way back.

For a server with a private IP address to access the internet, the firewall must perform source NAT to translate the private IP to a routable public IP. Without a NAT rule, return traffic cannot be routed back to the server. The security rule permits the traffic, but NAT is a separate configuration. The other options are less likely because application 'any' does not require a service, application override is not needed for basic connectivity, and the destination zone is typically part of the rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The security rule is missing a source NAT (SNAT) rule, so the server's private IP address is not translated and return traffic cannot find its way back.

    Why this is correct

    When a server with a private IP address (10.10.10.5) initiates traffic to the internet, the firewall must perform source NAT to translate the private IP to a public IP. Without a NAT rule, the packet is forwarded with the private source IP, which is not routable on the internet. Return traffic would be dropped by upstream routers. The security rule alone does not provide address translation; a NAT policy is required.

  • ✗

    The security rule is missing a service definition; the application 'any' does not automatically include all services.

    Why it's wrong here

    In PAN-OS, specifying application 'any' in a security rule does not require a separate service definition; the firewall will inspect the application and allow it if the application is recognized. The service field is only used when application is set to 'any' and the firewall cannot identify the application. Since the server cannot reach the internet, the issue is not the service definition but likely the missing NAT rule.

  • ✗

    The security rule is missing an application override because the server's traffic is not being identified correctly.

    Why it's wrong here

    Application override is used to force a specific application for custom or unknown traffic. However, the server cannot reach the internet at all, indicating a fundamental connectivity issue, not an application identification problem. Even if the application were misidentified, the firewall would still allow the traffic if the rule permits 'any'. The missing NAT rule is the more likely cause.

  • ✗

    The security rule is missing a destination zone; the firewall requires a destination zone to be specified for outbound traffic.

    Why it's wrong here

    A security rule must have a destination zone defined, but the administrator likely configured it as 'untrust' or the appropriate external zone. If the destination zone were missing, the rule would not be valid and would not appear in the rulebase. Since the rule exists and the server cannot reach the internet, the issue is not the destination zone but the lack of source NAT.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.