nerdexam
Palo_Alto_Networks

PCNSA · Question #376

An administrator needs to create a Security policy rule that matches DNS traffic sourced from either the LAN or VPN zones, destined for the DMZ or Untrust zones. The administrator does not want to mat

Sign in or unlock PCNSA to reveal the answer and full explanation for question #376. The question stem and answer options stay visible for context.

Submitted by andres_qro· Apr 18, 2026Securing Traffic

Question

An administrator needs to create a Security policy rule that matches DNS traffic sourced from either the LAN or VPN zones, destined for the DMZ or Untrust zones. The administrator does not want to match traffic where the source and destination zones are LAN, and also does not want to match traffic where the source and destination zones are VPN. Which Security policy rule type should they use?

Options

  • AInterzone
  • BUniversal
  • CIntrazone
  • DDefault

Unlock PCNSA to see the answer

You've previewed enough free PCNSA questions. Unlock PCNSA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Security Policy#Rule Types#Zones#Interzone Policy
Full PCNSA Practice