nerdexam
Palo_Alto_Networks

PCNSE6 · Question #21

A company has a web server behind their Palo Alto Networks firewall that they would like to make accessible to the public. They have decided to configure a destination NAT Policy rule. Given the…

The correct answer is C. Untrust-L3. See the full explanation below for the reasoning.

Question

A company has a web server behind their Palo Alto Networks firewall that they would like to make accessible to the public. They have decided to configure a destination NAT Policy rule. Given the following zone information:

DMZzone: DMZ-L3 Public zone: Untrust-L3 Web server zone: Trust-L3 Public IP address (Untrust-L3): 1.1.1.1 Private IP address (Trust-L3): 192.168.1.50 What should be configured as the destination zone on the Original Packet tab of the NAT Policy rule?

Options

  • ADMZ-L3
  • BAny
  • CUntrust-L3
  • DTrust-L3

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    18% (4)
  • C
    73% (16)
  • D
    5% (1)

Community Discussion

No community discussion yet for this question.

Full PCNSE6 Practice