exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 499 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 499
Topic #: 1
[All PCNSE Questions]

If an administrator wants to apply QoS to traffic based on source, what must be specified in a QoS policy rule?

  • A. Post-NAT destination address
  • B. Pre-NAT destination address
  • C. Pre-NAT source address
  • D. Post-NAT source address
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kalopilo
1 month ago
QoS to Traffic Based on Source ->If you want to apply QoS treatment to traffic based on source, you must specify the pre-NAT source address (such as pre-NAT source IP, pre-NAT source zone, pre-NAT destination IP, and post-NAT destination zone) in a QoS policy rule. Do not configure the QoS policy with the post-NAT source address if you want to apply QoS treatment for the source traffic
upvoted 1 times
...
evilCorpBot7494
9 months, 3 weeks ago
Selected Answer: C
In the Flow Logic, the Network part is performed before the Security part. QoS belongs to Network and NAT belongs to security (as counter-intuitive as that sounds)
upvoted 2 times
...
Marshpillowz
11 months, 2 weeks ago
Selected Answer: C
C is correct
upvoted 1 times
...
Mocix
1 year ago
Selected Answer: C
Check STEP 3 in the below link: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/configure-qos Because QoS is enforced on traffic as it egresses the firewall, your QoS policy rule is applied to traffic after the firewall has enforced all other security policy rules, including Network Address Translation (NAT) rules. If you want to apply QoS treatment to traffic based on source, you must specify the pre-NAT source address (such as pre-NAT source IP, pre-NAT source zone, pre-NAT destination IP, and post-NAT destination zone) in a QoS policy rule. Do not configure the QoS policy with the post-NAT source address if you want to apply QoS treatment for the source traffic.
upvoted 4 times
...
ansibai
1 year ago
Selected Answer: C
i tested this scenario in lab and i can see the hits only on the qos policy when we use pre-nat source address . even validated the same from the monitor session browser
upvoted 3 times
...
ansibai
1 year ago
Both link have different explanation https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/qos-concepts/qos-policy https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/configure-qos
upvoted 1 times
...
ansibai
1 year ago
Selected Answer: D
Because QoS is enforced on traffic as it egresses the firewall, your QoS policy rule is applied to traffic after the firewall has enforced all other security policy rules, including Network Address Translation (NAT) rules. If you want to apply QoS treatment to traffic based on source, make sure to specify the post-NAT source address in a QoS policy rule (do not use the pre-NAT source address).
upvoted 1 times
Mocix
1 year ago
I guess you meant C
upvoted 1 times
...
...
sov4
1 year, 5 months ago
Selected Answer: C
Per document: "Because QoS is enforced on traffic as it egresses the firewall, your QoS policy rule is applied to traffic after the firewall has enforced all other security policy rules, including Network Address Translation (NAT) rules. If you want to apply QoS treatment to traffic based on source, you must specify the pre-NAT source address (such as pre-NAT source IP, pre-NAT source zone, pre-NAT destination IP, and post-NAT destination zone) in a QoS policy rule. Do not configure the QoS policy with the post-NAT source address if you want to apply QoS treatment for the source traffic." https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/configure-qos
upvoted 2 times
...
pkevinkou
1 year, 8 months ago
Selected Answer: C
Because QoS is enforced on traffic as it egresses the firewall, your QoS policy rule is applied to traffic after the firewall has enforced all other security policy rules, including Network Address Translation (NAT) rules. If you want to apply QoS treatment to traffic based on source, you must specify the pre-NAT source address (such as pre-NAT source IP, pre-NAT source zone, pre-NAT destination IP, and post-NAT destination zone) in a QoS policy rule. Do not configure the QoS policy with the post-NAT source address if you want to apply QoS treatment for the source traffic. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/configure-qos
upvoted 3 times
PaloSteve
1 year, 5 months ago
Same statement as listed above in current documentation (https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/quality-of-service/configure-qos)
upvoted 1 times
...
...
daytonadave2011
1 year, 9 months ago
Selected Answer: C
The Answer is C. PsvdK's link explains it: Because QoS is enforced on traffic as it egresses the firewall, your QoS policy rule is applied to traffic after the firewall has enforced all other security policy rules, including Network Address Translation (NAT) rules. If you want to apply QoS treatment to traffic based on source, you must specify the pre-NAT source address (such as pre-NAT source IP, pre-NAT source zone, pre-NAT destination IP, and post-NAT destination zone) in a QoS policy rule. Do not configure the QoS policy with the post-NAT source address if you want to apply QoS treatment for the source traffic.
upvoted 4 times
...
PsvdK
1 year, 10 months ago
Answer is C: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/quality-of-service/configure-qos
upvoted 2 times
...
kewokil120
1 year, 10 months ago
Selected Answer: D
I argue D. QOS is after NAT. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0
upvoted 2 times
hcir
6 months, 3 weeks ago
QOS is enforced at egress, but the QOS logic is applied at the app-id stage, so after the security rule is enforced, which means that everything is pre-nat except for the destination zone which is post-nat, like the securiy rules
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago