exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 84 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 84
Topic #: 1
[All PCNSE Questions]

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT.

Which Security policy rule will allow traffic to flow to the web server?

  • A. Untrust (any) to Untrust (10.1.1.100), web browsing ג€" Allow
  • B. Untrust (any) to Untrust (1.1.1.100), web browsing ג€" Allow
  • C. Untrust (any) to DMZ (1.1.1.100), web browsing ג€" Allow
  • D. Untrust (any) to DMZ (10.1.1.100), web browsing ג€" Allow
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
trashboat
Highly Voted 3 years, 8 months ago
C is the correct answer. Remember for Security Policy lookup, the firewall uses Pre-NAT IP and Post-NAT Zone. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview.html
upvoted 14 times
...
Oswaldo_CCSM
Most Recent 2 weeks, 4 days ago
Selected Answer: D
In this scenario, Destination NAT (DNAT) is used to map the public IP address 1.1.1.100 (which is in the Untrust zone) to the private IP address 10.1.1.100 (which is in the DMZ zone). This allows external traffic destined for 1.1.1.100 to be forwarded to the web server at 10.1.1.100. To allow traffic to flow correctly, the security policy must allow the traffic to enter the DMZ zone using the 1.1.1.100 address, as the NAT process will map this public IP to the internal server.
upvoted 1 times
...
Yuval711
7 months ago
Selected Answer: D
D is the correct answer. the question is about security policy and the destination is 10.1.1.100
upvoted 1 times
...
Marshpillowz
11 months, 4 weeks ago
Selected Answer: C
Answer is C
upvoted 1 times
...
mbhuyan
1 year, 7 months ago
Selected Answer: B
Answer should B
upvoted 2 times
...
Woody
2 years, 1 month ago
Should that not be D based on https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-with-port-translation-example#id053beeb9-fde0-445b-99d0-5dd5a1000b7c ?
upvoted 1 times
DenskyDen
2 years ago
that should be C as mentioned on the question, it was natted.
upvoted 1 times
...
...
TAKUM1y
2 years, 3 months ago
Selected Answer: C
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview
upvoted 2 times
...
confusion
2 years, 10 months ago
Selected Answer: C
C. because security policy is pre-NAT IP + post-NAT ZONE.
upvoted 4 times
...
Kane002
3 years, 1 month ago
C is correct. I got this question on the PCNSA, and so I wouldn't expect to see it on the PCNSE.
upvoted 3 times
...
Angel123
3 years, 7 months ago
I believe the correct answer is 'B' Since this is DNAT setup, rule for security policy is: PRE-NAT addresses, POST-NAT zone. PCNSA study guide PAN OS 10.0, p.111
upvoted 2 times
Angel123
3 years, 7 months ago
Pardon me - 'C' is the answer with POST-NAT zone.
upvoted 4 times
...
...
shetoshandasa
3 years, 10 months ago
Correct Answer https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-many-mapping
upvoted 1 times
mmed
3 years, 9 months ago
the corrct answer is D
upvoted 1 times
webmanau
3 years, 9 months ago
No it's not. C is correct. the pre-NAT address is required as the destination in the security rule
upvoted 3 times
...
Prutser2
3 years, 6 months ago
no, C, It then evaluates and applies any security policies that match the packet based on the original (pre-NAT) source and destination addresses, but the post-NAT zones
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago