nerdexam
Palo_Alto_Networks

PCNSE · Question #563

Given the screenshot, how did the firewall handle the traffic?

The correct answer is B. Traffic was allowed by policy but denied by profile as a threat. Option B is correct because in next-generation firewalls (like FortiGate), traffic processing has two distinct stages: the firewall policy checks network criteria (source, destination, service) and permits the session, then security profiles (IPS, antivirus, etc.) inspect the…

Submitted by ricky.ec· Apr 18, 2026Core Concepts

Question

Given the screenshot, how did the firewall handle the traffic?

Exhibit

PCNSE question #563 exhibit

Options

  • ATraffic was allowed by policy but denied by profile as encrypted.
  • BTraffic was allowed by policy but denied by profile as a threat.
  • CTraffic was allowed by profile but denied by policy as a threat.
  • DTraffic was allowed by policy but denied by profile as a nonstandard port.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    92% (23)
  • D
    4% (1)

Explanation

Option B is correct because in next-generation firewalls (like FortiGate), traffic processing has two distinct stages: the firewall policy checks network criteria (source, destination, service) and permits the session, then security profiles (IPS, antivirus, etc.) inspect the content - in this case, the profile identified a threat within the allowed traffic and blocked it. The log would show "accept" at the policy level alongside a threat/IPS block action at the profile level.

Why the distractors fail:

  • A is wrong because encryption-blocked traffic would come from an SSL/deep inspection profile mismatch, not a threat detection - the scenario shows content inspection, not decryption failure.
  • C reverses the roles: policies evaluate network attributes (IP, port, interface), not threats - threat detection is exclusively the job of security profiles.
  • D is wrong because nonstandard port handling occurs at the policy level (service object matching), not inside a security profile.

Memory tip: Use the phrase "Policy opens the door; Profile searches the bag." If the door opened but the bag check found a weapon, that's exactly option B - policy allowed, profile denied as threat.

Topics

#Security Policies#Security Profiles#Threat Prevention#Traffic Processing

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice