PCNSE Troubleshoot Practice Question
Exhibit
2025/03/15 10:30:45,drop,203.0.113.10,10.1.1.200,https,443,trust,untrust,deny-rule,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any,any
Refer to the exhibit. The traffic log shows a drop event from source IP 203.0.113.10 to destination 10.1.1.200 on port 443. The rule matched is 'deny-rule'. What is the most likely reason for this drop?
⚠ Common exam trap
Many candidates confuse a security rule's 'deny' action with a block caused by a security profile (like Threat Prevention or URL Filtering), but the log explicitly shows the rule matched is 'deny-rule', indicating the drop is from the rule itself, not from any profile-based inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic matched a security rule that explicitly denies it
The traffic log explicitly states that the rule matched is 'deny-rule'. In Palo Alto Networks firewalls, when a security rule is configured with an action of 'Deny', any traffic matching that rule is dropped and logged with a 'deny' action. Since the log shows a drop event and the matched rule is 'deny-rule', the most direct and likely reason is that the traffic was explicitly denied by this security rule, not by any additional security profiles or external factors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The traffic matched a security rule that explicitly denies it
Why this is correct
The log names 'deny-rule' as the matched rule, so the drop results from explicit policy denial rather than an implicit default or threat inspection. Traffic matching that rule is discarded, satisfying the stem's requirement to explain the drop event from 203.0.113.10 to 10.1.1.200 on port 443.
- ✗
A threat prevention profile detected and blocked the session
Why it's wrong here
Threat prevention blocks appear as threat log entries with a specific signature or profile action, not as a security policy rule match; 'deny-rule' indicates policy denial. Threat prevention is tempting because it drops malicious sessions, but its verdicts are recorded separately from rule-based denies.
- ✗
The traffic was blocked because the application is not allowed
Why it's wrong here
The log matched 'deny-rule', a security policy rule, so the drop stems from policy action rather than application identification; App-ID enforcement would appear under an allow rule with an application-based block. Application control is tempting because it filters traffic by App-ID, but that mechanism is not what a deny-rule match indicates.
- ✗
The destination URL is categorized as prohibited
Why it's wrong here
URL categorisation applies to web filtering profiles, not to a security policy rule named 'deny-rule'; the log shows a rule match, so categorisation is not the cause. URL filtering is tempting because it blocks prohibited destinations on port 443, but it operates through a filtering profile, not a deny rule.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.