フリー問題

Palo Alto Networks Certified Network Security Analyst のフリー問題 7 / 20 問目

問題文

A company publishes a server with a destination NAT rule. Internal users who reach the same server by its public name are then found to need an extra rule. What is the reason such a case needs separate treatment?

選択肢

  1. Because the internal request leaves and returns through the same zone, so the translation and the security rule have to be written for that path as well.
  2. Because internal users cannot be identified by name so that the rule has to fall back on the source address of each of them.
  3. Because destination NAT is evaluated after the security policy so that the rule has to name the private address of the server.
  4. Because the destination NAT rule only applies to sessions that arrive on the interface that carries the public address, and internal users arrive on a different interface, which means the public name has to be resolved to the private address instead.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。