nerdexam
Palo_Alto_Networks

PCNSE7 · Question #191

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A…

The correct answer is C. Untrust (Any) to DMZ (10.1.1.1), web-browsing -Allow D. Untrust (Any) to DMZ (10.1.1.1), ssh 瑼llow. See the full explanation below for the reasoning.

Question

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and HOST B (10.1.1.101) receives SSH traffic.) Which two security policy rules will accomplish this configuration? (Choose two.)

Exhibit

PCNSE7 question #191 exhibit

Options

  • AUntrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
  • BUntrust (Any) to Untrust (10.1.1.1), ssh -Allow
  • CUntrust (Any) to DMZ (10.1.1.1), web-browsing -Allow
  • DUntrust (Any) to DMZ (10.1.1.1), ssh 瑼llow
  • EUntrust (Any) to DMZ (10.1.1.100.10.1.1.101), ssh, web-browsing -Allow

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    14% (7)
  • C
    75% (38)
  • E
    8% (4)

Community Discussion

No community discussion yet for this question.

Full PCNSE7 Practice