Drag steps to the numbered slots on the right, or tap a step then tap a slot.
PCNSE Securing Traffic and App-ID Practice Question
Order the steps to configure a security policy allowing HTTP traffic from the inside to the outside zone.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Specify source zone (Inside) and source addresses (any). Step 2: Specify destination zone (Outside) and destination addresses (any). Step 3: Select application (web-browsing) and set service to application-default. Step 4: Set action to allow. Step 5: Commit the configuration.
Configuring a security policy on Palo Alto Networks firewalls involves defining the traffic flow by specifying source and destination zones, then selecting the application and service, setting the action (allow or deny), and finally committing the changes. The correct order ensures logical consistency and proper policy enforcement. Common mistakes include swapping zones, setting action before application, or placing destination after application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Specify source zone (Inside) and source addresses (any). Step 2: Specify destination zone (Outside) and destination addresses (any). Step 3: Select application (web-browsing) and set service to application-default. Step 4: Set action to allow. Step 5: Commit the configuration.
Why this is correct
This is the correct order because security policies are built by first defining the traffic flow from source to destination, then specifying what application and service, then defining the action, and finally committing the change to make it effective.
- ✗
Step 1: Specify destination zone (Outside) and destination addresses (any). Step 2: Specify source zone (Inside) and source addresses (any). Step 3: Select application (web-browsing) and set service to application-default. Step 4: Set action to allow. Step 5: Commit the configuration.
Why it's wrong here
This is incorrect because the source zone should be defined before the destination zone for clarity and consistency, although functionally it might work. Standard practice is to define source first.
- ✗
Step 1: Specify source zone (Inside) and source addresses (any). Step 2: Select application (web-browsing) and set service to application-default. Step 3: Specify destination zone (Outside) and destination addresses (any). Step 4: Set action to allow. Step 5: Commit the configuration.
Why it's wrong here
This is incorrect because the destination zone must be specified before the application and service, as the policy match depends on destination zone.
- ✗
Step 1: Specify source zone (Inside) and source addresses (any). Step 2: Specify destination zone (Outside) and destination addresses (any). Step 3: Set action to allow. Step 4: Select application (web-browsing) and set service to application-default. Step 5: Commit the configuration.
Why it's wrong here
This is incorrect because the action should be set after the application and service are defined; otherwise, the action might be applied to a policy that doesn't yet have the correct application filtering.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.