Courseiva

PCNSE Core Concepts and Architecture Practice Question

An administrator is troubleshooting why a Security policy rule that allows traffic from the 'trust' zone to the 'untrust' zone is not matching for certain sessions. The administrator notices that the sessions are being denied by an interzone rule. What is the most likely cause?

⚠ Common exam trap

The trap here is focusing on application or user settings when the symptom clearly indicates a rule order problem, as interzone rules are often placed at the top for default protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The interzone rule is placed above the allow rule in the rulebase.

The most likely cause is that the interzone deny rule is positioned above the allow rule in the Security policy rulebase. Because PAN-OS evaluates rules from top to bottom and stops at the first match, a deny rule higher in the list will take precedence over a later allow rule. To resolve the issue, the administrator should move the allow rule above the interzone deny rule or adjust the interzone rule to be more specific so it does not match the intended traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The allow rule is configured with the application 'any' instead of a specific application.

    Why it's wrong here

    Using 'any' as the application in a Security policy rule does not prevent the rule from matching. In fact, it broadens the match criteria. The issue described is that traffic is being denied by an interzone rule, which indicates a rule order problem, not an application specification problem. Specifying a specific application would make the rule more restrictive, but it would not cause a different rule to be matched first.

  • ✗

    The allow rule is configured with a source user instead of a source IP address.

    Why it's wrong here

    Configuring a source user in a Security policy rule requires User-ID to be enabled and mappings to be present. If User-ID is not properly configured, the rule might not match, but the scenario states that an interzone rule is denying the traffic, which points to rule order rather than user identification. The presence of a source user does not inherently cause an interzone rule to take precedence.

  • ✗

    The allow rule is configured with a destination zone of 'untrust' but the traffic is destined to the firewall itself.

    Why it's wrong here

    If traffic is destined to the firewall itself, the destination zone would be the zone of the firewall interface, not 'untrust'. However, the scenario describes traffic from trust to untrust, which implies transit traffic. The problem is that an interzone rule is denying the sessions; this is a rule order issue, not a destination zone mismatch. The allow rule's destination zone being 'untrust' is correct for transit traffic.

  • ✓

    The interzone rule is placed above the allow rule in the rulebase.

    Why this is correct

    Security policy rules are evaluated top-down, and the first rule that matches the traffic is applied. If an interzone deny rule is positioned above the allow rule, it will match and block the traffic before the allow rule is evaluated. This is a common cause of unexpected denials when rule order is not carefully managed, especially when interzone rules are added for default protection.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.