Courseiva

PCNSE Deploy and Configure Firewalls Practice Question

Exhibit

Refer to the exhibit.
admin@PA-500> show interface ethernet1/2.10
Interface ethernet1/2.10
  VLAN: 20
  Virtual router: default
  IP netmask: 192.168.10.1/24
  Zone: VLAN10
  State: up

The administrator intended to create a sub-interface for VLAN 10 with IP 192.168.10.1/24. However, traffic from VLAN 10 is not being routed through this interface. Based on the exhibit, what is the cause?

⚠ Common exam trap

A common mix-up: candidates confuse the VLAN ID on the sub-interface with the IP subnet or zone name, assuming a mismatch in IP addressing or zone naming is the root cause, when in fact the VLAN tag mismatch is the direct and immediate reason traffic is not processed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VLAN ID is misconfigured as 20 instead of 10.

The exhibit shows the sub-interface is configured with VLAN ID 20, but the administrator intended VLAN 10. In Palo Alto Networks firewalls, sub-interfaces use 802.1Q VLAN tagging, and the VLAN ID must match the tag on incoming frames. Mismatched VLAN IDs cause the firewall to drop or ignore traffic because the sub-interface only processes frames with the configured tag.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The VLAN ID is misconfigured as 20 instead of 10.

    Why this is correct

    The sub-interface's VLAN tag must match the VLAN ID carried in the 802.1Q frame. Tagging it as VLAN 20 means frames arriving with VLAN 10 tags are dropped, so no traffic reaches the 192.168.10.1/24 gateway and routing fails.

  • ✗

    The IP netmask is /24 but should be /16.

    Why it's wrong here

    A /24 mask matches the stated 192.168.10.1/24 intent, so the netmask is not the fault; the exhibit's actual mismatch lies elsewhere, such as the VLAN tag or interface assignment. It tempts because wrong masks do break routing, and a /16 would be correct if the design required a larger subnet.

  • ✗

    The zone is incorrectly named 'VLAN10'.

    Why it's wrong here

    Zone names are arbitrary labels; the firewall routes between zones based on their assigned interfaces, not their names, so 'VLAN10' versus any other label changes nothing. It tempts because descriptive naming aids readability, and a matching name would be the sensible convention when defining a new Layer 3 zone.

  • ✗

    The virtual router is not correctly set.

    Why it's wrong here

    A sub-interface inherits its parent's virtual router, so an incorrect virtual router setting is not the cause here; the exhibit's actual fault is the VLAN tag or zone assignment. It tempts because virtual router misassignment does break routing, and it is correct when interfaces sit in the wrong routing instance.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.