| Exam Code/Number: | PCNSE6Join the discussion |
| Exam Name: | Palo Alto Networks Certified Network Security Engineer 6 |
| Certification: | Palo Alto Networks |
| Question Number: | 60 |
| Publish Date: | Jul 17, 2026 |
|
Rating
100%
|
|
A firewall is being attacked with a port scan. Which component can prevent this attack?
A company has a web server behind their Palo Alto Networks firewall that they would like to make accessible to the public. They have decided to configure a destination NAT Policy rule.
Given the following zone information:
-DMZzone: DMZ-L3 -Public zone: Untrust-L3 -Web server zone: Trust-L3 -Public IP address (Untrust-L3): 1.1.1.1 -Private IP address (Trust-L3): 192.168.1.50
What should be configured as the destination zone on the Original Packet tab of the NAT Policy rule?
Where can the maximum concurrent SSL VPN Tunnels be set for Vsys2 when provisioning a Palo Alto Networks firewall for multiple virtual systems?
After pushing a security policy from Panorama to a PA-3020 firewall, the firewall administrator notices that traffic logs from the PA-3020 are not appearing in Panorama's traffic logs.
What could be the problem?
Which two interface types provide support for network address translation (NAT)? Choose 2 answers