nerdexam
Palo_Alto_Networks

PCNSA · Question #221

An administrator needs to create a Security policy rule that matches DNS traffic within the LAN zone, and also needs to match DNS traffic within the DMZ zone. The administrator does not want to…

The correct answer is C. intrazone. Intrazone: A security policy allowing traffic between the same zone, this applies the rule to all matching traffic within the specified source zones (cannot specify a destination zone for intrazone For example, if setting the source zone to A and B, the rule would apply to all…

Submitted by mateo_ar· Apr 18, 2026Policy Evaluation and Management

Question

An administrator needs to create a Security policy rule that matches DNS traffic within the LAN zone, and also needs to match DNS traffic within the DMZ zone. The administrator does not want to allow traffic between the DMZ and LAN zones. Which Security policy rule type should they use?

Options

  • Adefault
  • Buniversal
  • Cintrazone
  • Dinterzone

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    4% (2)
  • C
    87% (41)
  • D
    2% (1)

Explanation

Intrazone: A security policy allowing traffic between the same zone, this applies the rule to all matching traffic within the specified source zones (cannot specify a destination zone for intrazone For example, if setting the source zone to A and B, the rule would apply to all traffic within zone A and all traffic within zone B, but not to traffic between zones A and B. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClomCAC

Topics

#Security Policy#Rule Types#Intrazone#Zones

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice