nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #210

View the diagram. What is the most restrictive yet fully functional rule to allow general Internet and SSH traffic into both the DMZ and Untrust/lnternet zones from each of the lOT/Guest and Trust Zon

The correct answer is B. Source: NAME: 04-A, TAGS: none, TYPE: universal, ZONE: Trust, ADDRESS: 172.16.16.0/24, 192.168.0.0/24, USER: any, DEVICE: any; Destination: ZONE: Untrust, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default. You've hit your limit · resets 5:20am (America/New_York)

Security Policy Configuration

Question

View the diagram. What is the most restrictive yet fully functional rule to allow general Internet and SSH traffic into both the DMZ and Untrust/lnternet zones from each of the lOT/Guest and Trust Zones? A. B. C. D.

Exhibits

NETSEC-ANALYST question #210 exhibit 1
NETSEC-ANALYST question #210 exhibit 2
NETSEC-ANALYST question #210 exhibit 3
NETSEC-ANALYST question #210 exhibit 4
NETSEC-ANALYST question #210 exhibit 5

Options

  • ASource: NAME: 03-A, TAGS: none, TYPE: universal, ZONE: Trust, ADDRESS: 172.16.16.0/24, 192.168.0.0/24, USER: any, DEVICE: any; Destination: ZONE: DMZ, ADDRESS: 10.0.1.0/24, 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default
  • BSource: NAME: 04-A, TAGS: none, TYPE: universal, ZONE: Trust, ADDRESS: 172.16.16.0/24, 192.168.0.0/24, USER: any, DEVICE: any; Destination: ZONE: Untrust, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default
  • CSource: NAME: 01-A, TAGS: none, TYPE: universal, ZONE: IOT-Guest, ADDRESS: 10.0.1.0/24, 172.16.16.0/12, USER: any, DEVICE: any; Destination: ZONE: DMZ, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing
  • DSource: NAME: 02-A, TAGS: none, TYPE: universal, ZONE: IOT-Guest, ADDRESS: 192.168.0.0/24, 172.16.16.0/24, USER: any, DEVICE: any; Destination: ZONE: DMZ, Untrust, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default, ACTION: Allow

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    70% (19)
  • C
    11% (3)
  • D
    15% (4)

Explanation

You've hit your limit · resets 5:20am (America/New_York)

Topics

#Security policy rules#zone-based firewall#DMZ#application-based policy

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice