PCNSE Exam Question 71

The NAT rule destination zone should be set to Outside because that is the zone where the post-NAT IP address of the server (192.168.10.10) belongs. The destination zone of a NAT rule is the zone where the translated IP address resides. Option A is incorrect because None is not a valid zone for a NAT rule. Option C is incorrect because DMZ is the zone where the pre-NAT IP address of the server (153.6 12.10) belongs, not the post-NAT IP address. Option D is incorrect because Inside is not a zone that is configured on the firewall.
An administrator is troubleshooting why video traffic is not being properly classified.
If this traffic does not match any QoS classes, what default class is assigned?
  • PCNSE Exam Question 72

    An engineer is tasked with configuring SSL forward proxy for traffic going to external sites.
    Which of the following statements is consistent with SSL decryption best practices?
  • PCNSE Exam Question 73

    A firewall administrator is trying to identify active routes learned via BGP in the virtual router runtime stats within the GUI. Where can they find this information?
  • PCNSE Exam Question 74

    Which statement about High Availability timer settings is true?
  • PCNSE Exam Question 75

    What happens when an A/P firewall cluster synchronies IPsec tunnel security associations (SAs)?