Palo_Alto_NetworksPalo_Alto_Networks
PCNSE · Question #695
PCNSE Question #695: Real Exam Question with Answer & Explanation
Sign in or unlock PCNSE to reveal the answer and full explanation for question #695. The question stem and answer options stay visible for context.
Submitted by salim_om· Apr 18, 2026Configuration Troubleshooting
Question
Review the information below. A firewall engineer creates a U-NAT rule to allow users in the trust zone access to a server in the same zone by using an external, public NAT IP for that server. Given the rule below, what change should be made to make sure the NAT works as expected?
Options
- AChange destination NAT zone to Trust_L3.
- BChange destination translation to Dynamic IP (with session distribution) using firewall eth1/2
- CChange Source NAT zone to Untrust_L3.
- DAdd source Translation to translate original source IP to the firewall eth1/2 interface translation.
Unlock PCNSE to see the answer
You've previewed enough free PCNSE questions. Unlock PCNSE for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#NAT Loopback#U-NAT#Source NAT (SNAT)#Firewall Configuration