nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #189

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100

The correct answer is A. Untrust (Any) to DMZ (1.1.1.100), ssh -Allow E. Untrust (Any) to DMZ (1.1.1.100), web-browsing -Allow. You've hit your limit · resets 5am (America/New_York)

Security Policy and NAT

Question

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic. Which two Security policy rules will accomplish this configuration? (Choose two.)

Exhibit

NETSEC-ANALYST question #189 exhibit

Options

  • AUntrust (Any) to DMZ (1.1.1.100), ssh -Allow
  • BUntrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
  • CUntrust (Any) to Untrust (10.1.1.1), ssh -Allow
  • DUntrust (Any) to DMZ (10.1.1.100, 10.1.1.101), ssh, web-browsing -Allow
  • EUntrust (Any) to DMZ (1.1.1.100), web-browsing -Allow

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    3% (1)
  • C
    7% (2)
  • D
    3% (1)

Explanation

You've hit your limit · resets 5am (America/New_York)

Topics

#DNAT#multi-server NAT#Security policy#zone-based firewall

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice