nerdexam
Palo_Alto_Networks

PCNSC · Question #46

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?

The correct answer is C. Untrust (any) to DMZ (1.1.1.100), web browsing - Allow. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration- examples/ destination-nat-exampleone-to-one-mapping.html#ide8f6a4b3-f875-4855-acb5-

Security Policy and Application Identification

Question

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?

Exhibit

PCNSC question #46 exhibit

Options

  • AUntrust (any) to Untrust (10.1.1.100), web browsing - Allow
  • BUntrust (any) to Untrust (1.1.1.100), web browsing - Allow
  • CUntrust (any) to DMZ (1.1.1.100), web browsing - Allow
  • DUntrust (any) to DMZ (10.1.1.100), web browsing - Allow

How the community answered

(55 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    80% (44)
  • D
    13% (7)

Explanation

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration- examples/ destination-nat-exampleone-to-one-mapping.html#ide8f6a4b3-f875-4855-acb5-

Topics

#DNAT#NAT policy#security policy zones#DMZ

Community Discussion

No community discussion yet for this question.

Full PCNSC Practice