Which Zone Pair and Rule Type will allow a successful connection for a user on the internet zone to a web server hosted in the DMZ zone? The web server is reachable using a destination Nat policy in the Palo Alto Networks firewall.
A . Zone Pair:
Source Zone: Internet
Destination Zone: DMZ
Rule Type:
“intrazone”
B . Zone Pair:
Source Zone: Internet
Destination Zone: DMZ
Rule Type:
“intrazone” or “universal”
C . Zone Pair:
Source Zone: Internet
Destination Zone: Internet
Rule Type:
“intrazone” or “universal”
D . Zone Pair:
Source Zone: Internet
Destination Zone: Internet
Rule Type:
“intrazone”
Answer: B
Explanation:
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/zone-protection-and-dos-protection/zone-defense/zone-defense-tools.html
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/networking/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping
Latest PCNSE Dumps Valid Version with 280 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund