nerdexam
Palo_Alto_Networks

PCNSA · Question #314

An administrator is creating a Security policy rule and sees that the destination zone is grayed out. While creating the rule, which option was selected to cause this?

The correct answer is D. Intrazone. When the rule type 'Intrazone' is selected, the policy applies to traffic originating and destined within the same zone. Because traffic must stay in a single zone by definition, PAN-OS automatically sets the destination zone to match the source zone and grays it out so it…

Submitted by zhang_li· Apr 18, 2026Configure

Question

An administrator is creating a Security policy rule and sees that the destination zone is grayed out. While creating the rule, which option was selected to cause this?

Options

  • AInterzone
  • BSource zone
  • CUniversal (default)
  • DIntrazone

How the community answered

(20 responses)
  • C
    5% (1)
  • D
    95% (19)

Explanation

When the rule type 'Intrazone' is selected, the policy applies to traffic originating and destined within the same zone. Because traffic must stay in a single zone by definition, PAN-OS automatically sets the destination zone to match the source zone and grays it out so it cannot be changed independently. Interzone applies to traffic between different zones (both source and destination are configurable). Universal (default) matches both intrazone and interzone traffic and keeps the destination zone editable.

Topics

#Security Policy#Intrazone Policy#Policy Configuration#Palo Alto Firewall

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice