exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 299 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 299
Topic #: 1
[All PCNSA Questions]

Which two matching criteria are used when creating a Security policy involving NAT? (Choose two.)

  • A. Pre-NAT address
  • B. Post-NAT address
  • C. Pre-NAT zone
  • D. Post-NAT zone
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NorthIdaho
Highly Voted 1 year, 6 months ago
I know that we have had "Pre-NAT IP, Post-NAT zone" drummed into our heads. But...the question is asking, which two "MATCHING CRITERIA" are used when creating a Security policy involving NAT. Go into the WebUI and look for yourself! Only zones are required. NOT addresses! Remember, these exams are as much "reading comprehension" as they are technical knowledge...it's C and D!
upvoted 13 times
...
Viga1991
Highly Voted 1 year, 10 months ago
A& D https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/datasheets/education/pcnsa-study-guide.pdf Question 11
upvoted 6 times
...
de7cdfd
Most Recent 1 month, 2 weeks ago
Selected Answer: CD
CD is correct
upvoted 1 times
...
joe1989
1 month, 3 weeks ago
Selected Answer: AD
Answer is A & D
upvoted 1 times
...
dragossky
4 months, 2 weeks ago
Selected Answer: AC
these should be the correct ones.
upvoted 1 times
...
cjace
7 months, 4 weeks ago
C. Pre-NAT zone A. Pre-NAT address These criteria are based on the original (pre-NAT) source and destination addresses1. It’s important to note that the firewall evaluates and applies any security policies that match the packet based on these pre-NAT details
upvoted 1 times
...
[Removed]
10 months ago
Selected Answer: CD
You only need at least a name, pre-nat zone and post-nat zon
upvoted 2 times
...
mariooiram87
1 year, 2 months ago
Selected Answer: AD
Pre-NAT IP, Post-NAT zone
upvoted 1 times
...
Sanjug2022
1 year, 6 months ago
A and D
upvoted 2 times
...
cert111
1 year, 7 months ago
Selected Answer: CD
This article reads, "You configure a NAT rule to match a packet’s source zone and destination zone, at a minimum." So I'm thinking it would be Pre-NAT zone and post-NAT zone, wouldn't it? https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview
upvoted 5 times
...
monterrosa
1 year, 10 months ago
Selected Answer: AD
Pregunta sacada de la guia de Palo Alto y marcan como respuesta Pre-NAT IP, post-NAT zone Q13. Which phrase is a simple way to remember how to configure Security policy rules where NAT was implemented? a. Post-NAT IP, pre-NAT zone b. Post-NAT IP, post-NAT zone c. Pre-NAT IP, post-NAT zone d. Pre-NAT IP, pre-NAT zone
upvoted 4 times
CerveceroJL
1 year, 4 months ago
gracias caballero
upvoted 1 times
...
...
baccalacca
1 year, 10 months ago
A and D Upon ingress, the firewall inspects the packet and does a route lookup to determine the egress interface and zone. Then the firewall determines if the packet matches one of the NAT rules that have been defined, based on source and/or destination zone. It then evaluates and applies any security policies that match the packet based on the original (pre-NAT) source and destination addresses, but the post-NAT zones. Finally, upon egress, for a matching NAT rule, the firewall translates the source and/or destination address and port numbers. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview
upvoted 2 times
...
fb48
1 year, 10 months ago
AB You configure a NAT rule to match a packet’s source zone and destination zone, at a minimum. In addition to zones, you can <b>configure matching criteria based on the packet’s destination interface, source and destination address, and service.</b>
upvoted 2 times
...
khaled_ellaboudy
1 year, 10 months ago
A & D Keep in mind that the translation of the IP address and port do not occur until the packet leaves the firewall. The NAT rules and security policies apply to the original IP address (the pre-NAT address). A NAT rule is configured based on the zone associated with a pre-NAT IP address. Security policies differ from NAT rules because security policies examine post-NAT zones to determine whether the packet is allowed or not. Because the very nature of NAT is to modify source or destination IP addresses, which can result in modifying the packet’s outgoing interface and zone, security policies are enforced on the post-NAT zone. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview
upvoted 3 times
...
mecacig953
1 year, 11 months ago
Selected Answer: AD
Pre-NAT IP ;Post-NAT Zone
upvoted 5 times
...
J2J2J2J
1 year, 11 months ago
Selected Answer: AB
Answer : A & B (Security Policy)
upvoted 1 times
OhEmGee
1 year, 11 months ago
Destination zone in Sec Pol is post-NAT (actual zone where packet is supposed to land).
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago