The Test Policy Match tool in PAN-OS allows administrators to simulate traffic against the current security policy set to verify how it will be handled. By inputting source/destination IPs, ports, protocols, and other parameters, it shows which rule matches and whether the traffic is allowed or denied, making it ideal for ensuring unwanted traffic is blocked.
Option A (Managed Devices Health) monitors device status, not policy logic. Option C (Preview Changes) shows configuration diffs, not traffic matching. Option D (Policy Optimizer) helps refine rules but doesn’t test specific traffic scenarios. Test Policy Match is the documented tool for this purpose.
[Reference: PAN-OS 11.2 Administrator’s Guide, "Policies" section - Test Policy Match Tool., , , , ]
Submit