Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 135 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 135
Topic #: 1
[All PCNSA Questions]


Given the network diagram, traffic should be permitted for both Trusted and Guest users to access general Internet and DMZ servers using SSH, web-browsing and SSL applications.
Which policy achieves the desired results?
A.

B.

C.

D.

Show Suggested Answer Hide Answer
Suggested Answer: B

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
westh4m1234
3 weeks, 2 days ago
on this question i agree with ALCOSTA35, however there is another question like this and they say answer is C (in this question it does not say RESTRICTED) BUT ON THE OTHER QUESTION IT SAYS RESTRICTED
upvoted 1 times
...
ALCOSTA35
3 weeks, 3 days ago
It cannot be C or D because the Source IP addresses are wrong. It cannot be A because restricts the destination address on Untristed zone to 1.1.1.0/24 and it should be Any (You don't know the addresses in Internet). So the only possible answer is B
upvoted 1 times
...
westh4m1234
4 weeks ago
Need an answer ASAP pls, on the PA firewall is it possible if you look at "C" can you have a source/Dst together like 172.16.16.0/24 as the source and 10.0.1.0/24 as the destination, even though it says /12 which looking at that answer C is wrong same for destination zone 192.168.0.0/24 as source and 1.1.1.0/24 as destination ???? in a nutshell C is wrong because of the mask /12 if it was /24 is the above possible ??/
upvoted 1 times
...
Janhattal
5 months ago
Not A - cause it only allowed the access to 1.1.1.* network.
upvoted 1 times
...
DlaEdu_Ex
1 year, 4 months ago
B is correct
upvoted 2 times
...
[Removed]
1 year, 8 months ago
B. Because A restricts internet to just the nexthop network
upvoted 2 times
...
BeforeScope
1 year, 10 months ago
Answer is B
upvoted 1 times
...
Banchan
2 years, 2 months ago
i think so A.Because both ip address is colect.
upvoted 1 times
...
Hyay
2 years, 2 months ago
Shouldn't it be A ?
upvoted 1 times
Hyay
2 years, 2 months ago
My bad, B is correct. Because A is too restrictive on internet
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...