nerdexam
Palo_Alto_Networks

PCNSA · Question #309

Which rule type is appropriate for matching traffic occurring within a specified zone?

The correct answer is C. Intrazone. An Intrazone rule is the appropriate rule type for matching and controlling traffic that originates and terminates within the boundaries of a single specified security zone.

Submitted by andreas_gr· Apr 18, 2026Policy Evaluation and Management

Question

Which rule type is appropriate for matching traffic occurring within a specified zone?

Options

  • AUniversal
  • BShadowed
  • CIntrazone
  • DInterzone

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (27)

Why each option

An Intrazone rule is the appropriate rule type for matching and controlling traffic that originates and terminates within the boundaries of a single specified security zone.

AUniversal

A Universal rule typically has a broader scope, applying generally across multiple zones or regardless of specific zones, rather than exclusively to traffic *within* one zone.

BShadowed

'Shadowed' describes a rule that is never matched due to a broader or identical rule above it, not a type of rule based on its zone scope.

CIntrazoneCorrect

Intrazone rules specifically apply to traffic where both the source and destination zones are identical, enabling granular security control over communication occurring within a single trusted network segment.

DInterzone

Interzone rules are designed to control traffic *between* different security zones, meaning the source and destination zones are distinct and not the same.

Concept tested: Intrazone security rule purpose

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/security-policy/security-policy-rule-types.html

Topics

#Firewall policies#Security rules#Intrazone traffic#Traffic types

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice