nerdexam
Palo_Alto_Networks

PCNSA · Question #285

Which type of policy allows an administrator to both enforce rules and take action?

The correct answer is B. Security. Security policies on Palo Alto Networks firewalls allow administrators to define match criteria (source/destination zones, addresses, users, applications, services) and then specify an action to take on matching traffic - such as allow, deny, drop, reset-client, reset-server…

Submitted by zhang_li· Apr 18, 2026Policy Evaluation and Management

Question

Which type of policy allows an administrator to both enforce rules and take action?

Options

  • AAuthentication
  • BSecurity
  • CNAT
  • DDecryption

How the community answered

(41 responses)
  • B
    93% (38)
  • C
    2% (1)
  • D
    5% (2)

Explanation

Security policies on Palo Alto Networks firewalls allow administrators to define match criteria (source/destination zones, addresses, users, applications, services) and then specify an action to take on matching traffic - such as allow, deny, drop, reset-client, reset-server, or reset-both. This combination of rule enforcement and explicit action selection is the defining characteristic of Security policies. Authentication policies enforce authentication rules but prompt users rather than directly acting on the session. NAT policies perform address translation but don't independently take allow/deny actions. Decryption policies control SSL/TLS inspection but still rely on Security policies to take action on the decrypted traffic.

Topics

#Security policies#Policy enforcement#Firewall rules

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice