exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 135 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 135
Topic #: 1
[All PCNSA Questions]


Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications.
Which policy achieves the desired results?
A.

B.

C.

D.

Show Suggested Answer Hide Answer
Suggested Answer: B

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
de7cdfd
1 month, 3 weeks ago
B is correct
upvoted 1 times
...
westh4m1234
2 months, 2 weeks ago
on this question i agree with ALCOSTA35, however there is another question like this and they say answer is C (in this question it does not say RESTRICTED) BUT ON THE OTHER QUESTION IT SAYS RESTRICTED
upvoted 1 times
...
ALCOSTA35
2 months, 2 weeks ago
It cannot be C or D because the Source IP addresses are wrong. It cannot be A because restricts the destination address on Untristed zone to 1.1.1.0/24 and it should be Any (You don't know the addresses in Internet). So the only possible answer is B
upvoted 1 times
...
westh4m1234
2 months, 3 weeks ago
Need an answer ASAP pls, on the PA firewall is it possible if you look at "C" can you have a source/Dst together like 172.16.16.0/24 as the source and 10.0.1.0/24 as the destination, even though it says /12 which looking at that answer C is wrong same for destination zone 192.168.0.0/24 as source and 1.1.1.0/24 as destination ???? in a nutshell C is wrong because of the mask /12 if it was /24 is the above possible ??/
upvoted 1 times
...
Janhattal
7 months ago
Not A - cause it only allowed the access to 1.1.1.* network.
upvoted 1 times
...
DlaEdu_Ex
1 year, 6 months ago
B is correct
upvoted 2 times
...
[Removed]
1 year, 10 months ago
B. Because A restricts internet to just the nexthop network
upvoted 2 times
...
BeforeScope
2 years ago
Answer is B
upvoted 1 times
...
Banchan
2 years, 3 months ago
i think so A.Because both ip address is colect.
upvoted 1 times
...
Hyay
2 years, 3 months ago
Shouldn't it be A ?
upvoted 1 times
Hyay
2 years, 3 months ago
My bad, B is correct. Because A is too restrictive on internet
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago