nerdexam
Palo_Alto_Networks

PCNSA · Question #105

Which three statements describe the operation of Security policy rules and Security Profiles? (Choose three.)

The correct answer is B. Security Profile should be used only on allowed traffic. C. Security Profile are attached to security policy rules. E. Security Policy rules can block or allow traffic. Security policy rules control network traffic by either allowing or blocking it, and Security Profiles are subsequently attached to these rules to perform deeper threat inspection on the permitted traffic.

Submitted by fernanda_arg· Apr 18, 2026Securing Traffic

Question

Which three statements describe the operation of Security policy rules and Security Profiles? (Choose three.)

Options

  • ASecurity policy rules inspect but do not block traffic.
  • BSecurity Profile should be used only on allowed traffic.
  • CSecurity Profile are attached to security policy rules.
  • DSecurity Policy rules are attached to Security Profiles.
  • ESecurity Policy rules can block or allow traffic.

How the community answered

(16 responses)
  • A
    6% (1)
  • B
    94% (15)

Why each option

Security policy rules control network traffic by either allowing or blocking it, and Security Profiles are subsequently attached to these rules to perform deeper threat inspection on the permitted traffic.

ASecurity policy rules inspect but do not block traffic.

Security policy rules can indeed block traffic; they are not limited to inspection and allowing, as denying traffic is a primary security function to enforce access control.

BSecurity Profile should be used only on allowed traffic.Correct

Security Profiles are designed to apply advanced threat prevention and inspection to traffic that has already been permitted by a Security policy rule, ensuring only desired traffic is further scrutinized for threats.

CSecurity Profile are attached to security policy rules.Correct

Security Profiles are configured independently for various threat prevention categories (e.g., Antivirus, Anti-Spyware, URL Filtering) and are then referenced within a Security policy rule to apply these inspections to matching traffic.

DSecurity Policy rules are attached to Security Profiles.

This statement reverses the relationship; Security Profiles are applied to security policy rules to enhance their inspection capabilities, not the other way around.

ESecurity Policy rules can block or allow traffic.Correct

The fundamental function of a security policy rule is to determine whether traffic is permitted (allowed) to pass through the firewall or denied (blocked), based on criteria like source, destination, application, and service, thus acting as an access control mechanism.

Concept tested: Palo Alto Networks Security Policies and Profiles

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy-rules/security-policy-overview

Topics

#Security Policy#Security Profiles#Traffic Flow#Policy Action

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice