PCNSA Exam QuestionsBrowse all questions from this exam

PCNSA Exam - Question 167


Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic.

Which two Security policy rules will accomplish this configuration? (Choose two.)

Show Answer
Correct Answer: AE

For the configuration described, which directs HTTP traffic to Host A (10.1.1.100) and SSH traffic to Host B (10.1.1.101), the correct security policy rules need to match the destination addresses post-NAT and the appropriate ports for the services. Traffic directed to Host A using HTTP should allow web-browsing to 1.1.1.100 post-NAT, hence the rule Untrust to DMZ (1.1.1.100), web-browsing - Allow is correct. Similarly, for Host B, allowing ssh traffic to 1.1.1.100 post-NAT matches the rule Untrust to DMZ (1.1.1.100), ssh - Allow. These ensure the correct mapping and security policy for both types of traffic via Destination NAT.

Discussion

6 comments
Sign in to comment
DlaEdu_ExOptions: AE
Jul 3, 2023

To define Destination, Security policy uses Post-NAT zone and Pre-NAT address

skaezOptions: DE
Jun 25, 2023

If we check DNAT, HTTP is for 1.1.1.100 so answer E And answer E is for the 2 DNAT and correct ports

OteslarOptions: AE
Dec 13, 2022

A and E are correct answers.

blahblah1234567890000
Jan 18, 2023

I dont understand how a could possibly be correct since the other server is supposed to get the SSH traffic.

blahblah1234567890000
Jan 18, 2023

Nevermind I misread the IP.

ntirOptions: AE
Feb 15, 2023

A and E

blu_gandalfOptions: DE
May 16, 2023

i think its D , E

blu_gandalf
May 16, 2023

i was worng sorry

JanhattalOptions: AE
Jun 22, 2024

A, E are correct