PCNSA · Question #350
Given the network diagram, which two statements are true about traffic between the User and Server networks? (Choose two.)
The correct answer is A. Traffic is permitted through the default Intrazone "allow" rule. D. Traffic restrictions are possible by modifying Intrazone rules. In Palo Alto Networks PAN-OS, when two networks (User and Server) reside in the same security zone, traffic between them is classified as intrazone traffic. By default, the firewall includes a default Intrazone 'allow' rule that permits all intrazone traffic - making statement…
Question
Given the network diagram, which two statements are true about traffic between the User and Server networks? (Choose two.)
Exhibit
Options
- ATraffic is permitted through the default Intrazone "allow" rule.
- BTraffic restrictions are not possible because the networks are in the same zone.
- CTraffic is permitted through the default Interzone "allow" rule.
- DTraffic restrictions are possible by modifying Intrazone rules.
How the community answered
(24 responses)- A88% (21)
- B4% (1)
- C8% (2)
Explanation
In Palo Alto Networks PAN-OS, when two networks (User and Server) reside in the same security zone, traffic between them is classified as intrazone traffic. By default, the firewall includes a default Intrazone 'allow' rule that permits all intrazone traffic - making statement A true. Intrazone rules can be modified (cloned, overridden with deny rules, or replaced) by an administrator to restrict traffic within the same zone - making statement D true. Statement B is false because restrictions are possible via intrazone rule modifications. Statement C is false because interzone rules govern traffic between different zones, not same-zone traffic.
Topics
Community Discussion
No community discussion yet for this question.
