PCNSE Exam Question 101

The NAT rule destination zone should be set to Outside because that is the zone where the post-NAT IP address of the server (192.168.10.10) belongs. The destination zone of a NAT rule is the zone where the translated IP address resides. Option A is incorrect because None is not a valid zone for a NAT rule. Option C is incorrect because DMZ is the zone where the pre-NAT IP address of the server (153.6 12.10) belongs, not the post-NAT IP address. Option D is incorrect because Inside is not a zone that is configured on the firewall.
An administrator is troubleshooting why video traffic is not being properly classified.
If this traffic does not match any QoS classes, what default class is assigned?
  • PCNSE Exam Question 102

    An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)
  • PCNSE Exam Question 103

    How can an administrator use the Panorama device-deployment option to update the apps and threat version of an HA pair of managed firewalls?
  • PCNSE Exam Question 104

    How should an administrator enable the Advance Routing Engine on a Palo Alto Networks firewall?
  • PCNSE Exam Question 105

    Which log type would provide information about traffic blocked by a Zone Protection profile?