nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #181

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?

The correct answer is D. Untrust (any) to DMZ (1.1.1.100), web browsing -Allow. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration- examples/destination-nat-exampleone-to-one-mapping

Security Policy and NAT

Question

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?

Exhibit

NETSEC-ANALYST question #181 exhibit

Options

  • AUntrust (any) to DMZ (10.1.1.100), web browsing -Allow
  • BUntrust (any) to Untrust (1.1.1.100), web browsing -Allow
  • CUntrust (any) to Untrust (10.1.1.100), web browsing -Allow
  • DUntrust (any) to DMZ (1.1.1.100), web browsing -Allow

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    14% (7)
  • C
    6% (3)
  • D
    76% (37)

Explanation

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration- examples/destination-nat-exampleone-to-one-mapping

Topics

#DNAT#Security policy#zone-based firewall#pre-NAT IP matching

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice