
Palo Alto NetworksCertified Network Security Analyst
Domain 2Objective 2
2.2 Create and Apply NAT Policies NETWORK-SECURITY-ANALYST Practice Questions (Page 4)
Part of the Policy Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.
21questions here
5free pages
7concepts
30%of the exam
Questions 16–20
- 16
An administrator is troubleshooting a NAT issue where internal users can access the internet, but the return traffic is not reaching them. The firewall has a source NAT policy that translates Trust to Untrust. The administrator checks the session table and sees that the session is established. What is the most likely cause?
Select an answer first - 17
Which type of NAT policy is used to translate the source address of outbound traffic from a private network to a public address?
Select an answer first - 18
When would you use a destination NAT policy on a Palo Alto Networks firewall?
Select an answer first - 19
Users report that they cannot reach an internal server from the internet. The firewall has a destination NAT policy that translates the public IP 203.0.113.20 to the private IP 10.10.1.20 for service HTTPS. A security policy allows HTTPS from the Untrust zone to the DMZ zone. The administrator checks the traffic logs and sees that packets are being dropped. What should the administrator check next to diagnose the issue?
Select an answer first - 20
An administrator has configured a destination NAT policy for a web server. The security policy allows HTTPS from Untrust to DMZ. Users can access the web server from the internet, but the server logs show that the source IP of the clients is the firewall's internal IP (10.10.1.1) instead of the actual client IP. What is the most likely cause?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.