nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #160

Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications. Which policy achieves t

The correct answer is B. NAME TAGS TYPE ZONE ADDRESS USER DEVICE ZONE ADDRESS DEVICE APPLICATION SERVICE 04-A none universal IOT-Guest 172.16.16.0/24 any any DMZ any ssh app TRUST 192.16.0.0/24 Untrust web-browsing ssl. You've hit your limit · resets 5:20am (America/New_York)

Security Policy Management

Question

Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications. Which policy achieves the desired results? A. B. C. D.

Exhibits

NETSEC-ANALYST question #160 exhibit 1
NETSEC-ANALYST question #160 exhibit 2
NETSEC-ANALYST question #160 exhibit 3
NETSEC-ANALYST question #160 exhibit 4
NETSEC-ANALYST question #160 exhibit 5

Options

  • ANAME TAGS TYPE ZONE ADDRESS USER DEVICE ZONE ADDRESS DEVICE APPLICATION SERVICE 03-A none universal TRUST 172.16.16.0/24 any any DMZ 1.1.1.0/24 any ssh app 192.16.0.0/24 web-browsing ssl
  • BNAME TAGS TYPE ZONE ADDRESS USER DEVICE ZONE ADDRESS DEVICE APPLICATION SERVICE 04-A none universal IOT-Guest 172.16.16.0/24 any any DMZ any ssh app TRUST 192.16.0.0/24 Untrust web-browsing ssl
  • CNAME TAGS TYPE ZONE ADDRESS USER DEVICE ZONE ADDRESS DEVICE APPLICATION SERVICE 01-A none universal TRUST 172.16.16.0/24 any any DMZ 1.1.1.0/24 any ssh app 172.16.12.0/24 Untrust 192.16.0.0/24 web-browsing ssl
  • DNAME TAGS TYPE ZONE ADDRESS USER DEVICE ZONE ADDRESS DEVICE APPLICATION SERVICE 02-A none universal IOT-Guest 172.16.16.0/24 any any DMZ 1.1.1.0/24 any ssh app TRUST 192.16.0.0/24 Untrust 192.16.0.0/24 web-browsing ssl

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    75% (18)
  • C
    4% (1)
  • D
    13% (3)

Explanation

You've hit your limit · resets 5:20am (America/New_York)

Topics

#multi-zone policy#source zone grouping#application policy#trusted and guest users

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice