nerdexam
Palo_Alto_Networks

PCNSA · Question #272

An administrator would like to override the default deny action for a given application, and instead would like to block the traffic. Which security policy action causes this?

The correct answer is A. Drop. The Drop security policy action silently drops the traffic. This overrides the default deny action for an application, and instead blocks the traffic. The Drop, send ICMP Unreachable action also drops the traffic, but it also sends an ICMP unreachable message to the source…

Submitted by marco_it· Apr 18, 2026Policy Evaluation and Management

Question

An administrator would like to override the default deny action for a given application, and instead would like to block the traffic. Which security policy action causes this?

Options

  • ADrop
  • BDrop, send ICMP Unreachable
  • CReset both
  • DReset client

How the community answered

(63 responses)
  • A
    89% (56)
  • B
    2% (1)
  • C
    3% (2)
  • D
    6% (4)

Explanation

The Drop security policy action silently drops the traffic. This overrides the default deny action for an application, and instead blocks the traffic. The Drop, send ICMP Unreachable action also drops the traffic, but it also sends an ICMP unreachable message to the source device. The Reset both and Reset client actions send a TCP reset to both the source and destination devices. Therefore, the Drop security policy action is the only one that will override the default deny action for an application and block the traffic.

Topics

#Security Policies#Policy Actions#Traffic Blocking#Firewall Rules

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice