pcnsa question 155 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 155

An administrator needs to create a Security policy rule that matches DNS traffic sourced from either the LAN or VPN zones, destined for the DMZ or Untrust zones.

The administrator does not want to match traffic where the source and destination zones are LAN, and also does not want to match traffic where the source and destination zones are VPN.

Which Security policy rule type should they use?

  • A. Interzone
  • B. Universal
  • C. Intrazone
  • D. Default
Answer:

b

User Votes:
A 1 votes
50%
B
50%
C
50%
D
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

in other words the admin doesn't want to match intrazone traffic it is clearly an interzone traffic as the universal means the whole thing. A is the correct answer.