nerdexam
Palo_Alto_Networks

PCNSA · Question #299

By default, which action is assigned to the interzone-default rule?

The correct answer is B. Deny. By default, the interzone-default rule is configured to deny all traffic attempting to cross between different security zones unless explicitly permitted by a more specific rule.

Submitted by carlos_mx· Apr 18, 2026Securing Traffic

Question

By default, which action is assigned to the interzone-default rule?

Options

  • AAllow
  • BDeny
  • CReset-client
  • DReset-server

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    93% (43)
  • C
    2% (1)

Why each option

By default, the interzone-default rule is configured to deny all traffic attempting to cross between different security zones unless explicitly permitted by a more specific rule.

AAllow

Allowing interzone traffic by default would pose a significant security risk, as it would expose internal networks to unauthorized access without specific policy enforcement.

BDenyCorrect

The default security posture for firewalls is to deny interzone traffic, ensuring that only explicitly permitted communication can occur between distinct network segments, following a zero-trust principle.

CReset-client

While 'reset-client' is a possible action, it is not the default for the interzone-default rule, which typically performs a silent deny to avoid revealing network topology.

DReset-server

Similar to 'reset-client,' 'reset-server' is an action, but the default for the interzone-default rule is a silent denial of unpermitted traffic.

Concept tested: Default interzone firewall rule action

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy/security-policy-rules.html

Topics

#Default Security Policy#Security Zones#Interzone Traffic#Firewall Rules

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice