PCNSE Deploy and Configure Firewalls Practice Question
An administrator is configuring a new Palo Alto Networks firewall and wants to ensure that a specific server (10.10.10.5) can communicate with any destination on the internet, but only when the server initiates the connection. The server must be able to receive return traffic. The administrator creates a security rule allowing traffic from the trust zone to the untrust zone with source 10.10.10.5 and application 'any'. However, the server cannot reach the internet. The administrator verifies that the default route is correct and that the server can ping the firewall's interface. What is the most likely reason the server cannot reach the internet?
⚠ Common exam trap
The trap here is assuming that a security rule allowing traffic is sufficient for outbound internet access, forgetting that source NAT is required for private IP addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The security rule is missing a source NAT (SNAT) rule, so the server's private IP address is not translated and return traffic cannot find its way back.
For a server with a private IP address to access the internet, the firewall must perform source NAT to translate the private IP to a routable public IP. Without a NAT rule, return traffic cannot be routed back to the server. The security rule permits the traffic, but NAT is a separate configuration. The other options are less likely because application 'any' does not require a service, application override is not needed for basic connectivity, and the destination zone is typically part of the rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The security rule is missing a source NAT (SNAT) rule, so the server's private IP address is not translated and return traffic cannot find its way back.
Why this is correct
When a server with a private IP address (10.10.10.5) initiates traffic to the internet, the firewall must perform source NAT to translate the private IP to a public IP. Without a NAT rule, the packet is forwarded with the private source IP, which is not routable on the internet. Return traffic would be dropped by upstream routers. The security rule alone does not provide address translation; a NAT policy is required.
- ✗
The security rule is missing a service definition; the application 'any' does not automatically include all services.
Why it's wrong here
In PAN-OS, specifying application 'any' in a security rule does not require a separate service definition; the firewall will inspect the application and allow it if the application is recognized. The service field is only used when application is set to 'any' and the firewall cannot identify the application. Since the server cannot reach the internet, the issue is not the service definition but likely the missing NAT rule.
- ✗
The security rule is missing an application override because the server's traffic is not being identified correctly.
Why it's wrong here
Application override is used to force a specific application for custom or unknown traffic. However, the server cannot reach the internet at all, indicating a fundamental connectivity issue, not an application identification problem. Even if the application were misidentified, the firewall would still allow the traffic if the rule permits 'any'. The missing NAT rule is the more likely cause.
- ✗
The security rule is missing a destination zone; the firewall requires a destination zone to be specified for outbound traffic.
Why it's wrong here
A security rule must have a destination zone defined, but the administrator likely configured it as 'untrust' or the appropriate external zone. If the destination zone were missing, the rule would not be valid and would not appear in the rulebase. Since the rule exists and the server cannot reach the internet, the issue is not the destination zone but the lack of source NAT.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.