View the diagram. What is the most restrictive, yet fully functional rule, to allow general Internet and SSH traffic into both the DMZ and Untrust/Internet zones from each of the IOT/Guest and Trust Zones? A.
The answer is B.
A is incorrect - no internet access, DST addresses are too strictly definedd;
C is incorrect - SRC and DST addresses do not correspond to Zones;
D is incorrect - the SRC address does not match the SRC zone.
Please, fix this. C has the wrong Source Subnet IP address for the Trust. It is wrong.
The only possible answer is B. A only allows traffic to 1.1.1.0/24 instead of all Internet, which would be correct if we use NAT policy, but the question does not mention NAT.
I think the answer B is good but not restrictive, however A could be a better choice as it is more restrictive and if we allow it to the destination address of 1.1.1.0/24 using services "SSL,SSH and web-browsing will it be able to use the internet? if this is a yes then A would be the best answer if not its going to have to be B. please respond anyone.
C has the wring address and mask /12 for the source zones. B does not specify the destination address, so it is functional but it is not restrict. A is the answer because restricts to only the shown subnets.
The answer is A because the question is asking for the most restrictive means to access the DMZ and untrust zones from the Guest and Trust zones. In answer A, the rule restricts access to the destination IP address subnet ranges of the DMZ and Untrust zone destination addresses, whereas answer B pretty much says you can connect to any address in the DMZ and Untrust subnets. A is the correct answer.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
DlaEdu_Ex
Highly Voted 1 year, 9 months agoAredus
Highly Voted 8 months agoDIG_Tofu
7 months, 4 weeks agoALCOSTA35
Most Recent 2 weeks, 1 day agowesth4m1234
2 weeks, 1 day agoALCOSTA35
1 week, 6 days agoALCOSTA35
1 month, 2 weeks agodc6a988
4 months, 2 weeks agoJanhattal
4 months, 3 weeks agocjace
5 months, 3 weeks agoNotimig
12 months agoclaudio392
1 year, 2 months agoclaudio392
1 year, 2 months agoSanjug2022
1 year, 4 months agoKalender
1 year, 6 months agoSly04
11 months, 3 weeks agomadt
1 year, 6 months agoDatITGuyTho1337
1 year, 7 months agoPaloCert
1 year, 8 months agoWisley
1 year, 8 months ago