nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #376

An administrator needs to create a Security policy rule that matches DNS traffic sourced from either the LAN or VPN zones, destined for the DMZ or Untrust zones. The administrator does not want to…

The correct answer is A. Interzone. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/policy/security-policy/components- of-a-security-policy-rule

Security Policy Configuration

Question

An administrator needs to create a Security policy rule that matches DNS traffic sourced from either the LAN or VPN zones, destined for the DMZ or Untrust zones. The administrator does not want to match traffic where the source and destination zones are LAN, and also does not want to match traffic where the source and destination zones are VPN. Which Security policy rule type should they use?

Options

  • AInterzone
  • BUniversal
  • CIntrazone
  • DDefault

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    11% (3)
  • C
    4% (1)
  • D
    7% (2)

Explanation

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/policy/security-policy/components- of-a-security-policy-rule

Topics

#interzone policy#security policy rule types#zone-based firewall#traffic matching logic

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice