Palo_Alto_Networks
NETSEC-ANALYST · Question #210
View the diagram. What is the most restrictive yet fully functional rule to allow general Internet and SSH traffic into both the DMZ and Untrust/lnternet zones from each of the lOT/Guest and Trust Zon
The correct answer is B. Source: NAME: 04-A, TAGS: none, TYPE: universal, ZONE: Trust, ADDRESS: 172.16.16.0/24, 192.168.0.0/24, USER: any, DEVICE: any; Destination: ZONE: Untrust, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default. You've hit your limit · resets 5:20am (America/New_York)
Security Policy Configuration
Question
View the diagram. What is the most restrictive yet fully functional rule to allow general Internet and SSH traffic into both the DMZ and Untrust/lnternet zones from each of the lOT/Guest and Trust Zones? A. B. C. D.
Exhibits
Options
- ASource: NAME: 03-A, TAGS: none, TYPE: universal, ZONE: Trust, ADDRESS: 172.16.16.0/24, 192.168.0.0/24, USER: any, DEVICE: any; Destination: ZONE: DMZ, ADDRESS: 10.0.1.0/24, 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default
- BSource: NAME: 04-A, TAGS: none, TYPE: universal, ZONE: Trust, ADDRESS: 172.16.16.0/24, 192.168.0.0/24, USER: any, DEVICE: any; Destination: ZONE: Untrust, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default
- CSource: NAME: 01-A, TAGS: none, TYPE: universal, ZONE: IOT-Guest, ADDRESS: 10.0.1.0/24, 172.16.16.0/12, USER: any, DEVICE: any; Destination: ZONE: DMZ, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing
- DSource: NAME: 02-A, TAGS: none, TYPE: universal, ZONE: IOT-Guest, ADDRESS: 192.168.0.0/24, 172.16.16.0/24, USER: any, DEVICE: any; Destination: ZONE: DMZ, Untrust, ADDRESS: 1.1.1.0/24, USER: any, DEVICE: any, APPLICATION: ssh, web-browsing, default, ACTION: Allow
How the community answered
(27 responses)- A4% (1)
- B70% (19)
- C11% (3)
- D15% (4)
Explanation
You've hit your limit · resets 5:20am (America/New_York)
Topics
#Security policy rules#zone-based firewall#DMZ#application-based policy
Community Discussion
No community discussion yet for this question.




