Palo Alto Networks Certified Network Security Administrator (PCNSA) — Question 281
An administrator is trying to understand which NAT policy is being matched.
In what order does the firewall evaluate NAT policies?
Answer options
- A. Dynamic IP and Port first, then Static, and finally Dynamic IP
- B. From top to bottom
- C. Static NAT rules first, then lop down
- D. Static NAT rules first, then Dynamic
Correct answer: B
Explanation
The correct answer is B because firewalls evaluate NAT policies in a top-to-bottom manner, ensuring that the first applicable rule is applied. The other options incorrectly suggest different orders or priorities that do not align with how NAT policies are processed.