Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Analyst

Domain 2Objective 2

2.2 Create and Apply NAT Policies NETWORK-SECURITY-ANALYST Practice Questions (Page 1)

Part of the Policy Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.

21questions here
5free pages
7concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A firewall has two NAT policies: Policy 1 translates traffic from the Trust zone to the Untrust zone with source address 192.168.1.0/24 to 203.0.113.10. Policy 2 translates traffic from the Trust zone to the Untrust zone with source address 192.168.1.0/24 and destination port 80 to 203.0.113.11. The administrator notices that web traffic from the Trust zone is being translated to 203.0.113.10 instead of 203.0.113.11. What is the most likely cause?

    Select an answer first
  2. 2foundation · easy

    In a source NAT policy, what does the 'Dynamic IP and Port' (DIPP) option allow?

    Select an answer first
  3. 3foundation · easy

    Which tool can be used on a Palo Alto Networks firewall to verify that NAT is being applied correctly to traffic?

    Select an answer first
  4. 4foundation · easy

    Which of the following is a required attribute in the 'Original Packet' tab of a NAT policy?

    Select an answer first
  5. 5foundation · easy

    In a Palo Alto Networks firewall, what is the relationship between NAT policies and security policies?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.