nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #46

A server-admin in the USERS-zone requires SSH-access to all possible servers in all current and future Public Cloud environments. All other required connections have already been enabled between the…

The correct answer is B. Create a security-rule that allows traffic from zone USERS to OUTSIDE to allow traffic from any. You've hit your limit · resets 5am (America/New_York)

Security Policy Configuration

Question

A server-admin in the USERS-zone requires SSH-access to all possible servers in all current and future Public Cloud environments. All other required connections have already been enabled between the USERS-and the OUTSIDE-zone. What configuration-changes should the Firewall- admin make?

Options

  • ACreate a custom-service-object called SERVICE-SSH for destination-port-TCP-22. Create a
  • BCreate a security-rule that allows traffic from zone USERS to OUTSIDE to allow traffic from any
  • CIn addition to option a, a custom-service-object called SERVICE-SSH-RETURN that contains
  • DIn addition to option c, an additional rule from zone OUTSIDE to USERS for application SSH from

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    79% (27)
  • C
    3% (1)
  • D
    6% (2)

Explanation

You've hit your limit · resets 5am (America/New_York)

Topics

#security rules#inter-zone SSH#service objects#zone-based policy

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice