nerdexam
Palo_Alto_Networks

PCNSA · Question #186

Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP Addresses list?

The correct answer is B. source address. An External Dynamic List (EDL) of Known Malicious IP Addresses contains IPs that are initiating malicious traffic toward your network. Since these IPs are the originators of the threat, they appear as the source of inbound connections. To block traffic coming FROM these…

Submitted by saadiq_pk· Apr 18, 2026Securing Traffic

Question

Which Security policy match condition would an administrator use to block traffic from IP addresses on the Palo Alto Networks EDL of Known Malicious IP Addresses list?

Options

  • Adestination address
  • Bsource address
  • Cdestination zone
  • Dsource zone

How the community answered

(71 responses)
  • A
    3% (2)
  • B
    93% (66)
  • C
    1% (1)
  • D
    3% (2)

Explanation

An External Dynamic List (EDL) of Known Malicious IP Addresses contains IPs that are initiating malicious traffic toward your network. Since these IPs are the originators of the threat, they appear as the source of inbound connections. To block traffic coming FROM these malicious IPs, you reference the EDL in the 'source address' match condition of a Security policy rule with a Deny action. Using 'destination address' would block traffic going TO those IPs, which is a different use case. Zones do not directly reference IP-based EDLs.

Topics

#Security Policy#External Dynamic List (EDL)#Source Address#Policy Matching

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice