easyMultiple ChoiceObjective-mapped
PCNSA Practice Question: A company uses destination NAT to translate a…
A company uses destination NAT to translate a public IP to an internal server. They need to ensure that traffic sourced from the internal network to the public IP is also translated correctly. What is the best practice to achieve this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a source NAT rule for internal traffic destined to the public IP, translating it to the internal server IP.
When internal users access the public IP that is destination NATed to an internal server, the traffic must be source NATed to ensure symmetric routing. Without source NAT, the server sees the source as the internal client IP and sends the response directly to the client, causing asymmetric routing and connection failures. Implementing a source NAT rule for internal traffic destined to the public IP (hairpin NAT) ensures the firewall translates the source to its own internal IP, so the response goes back through the firewall. Option A is incorrect because disabling NAT on the loopback interface does not address the issue. Option B is incorrect because policy-based forwarding (PBF) is used for routing decisions, not NAT. Option C is incorrect because an additional destination NAT rule would not change the source address; source NAT is required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable NAT on the internal zone's loopback interface.
Why it's wrong here
Loopback interfaces are not involved in NAT hairpinning for this scenario.
- ✗
Configure a policy-based forwarding rule to redirect internal traffic.
Why it's wrong here
Policy-based forwarding is used for routing decisions, not for NAT hairpinning.
- ✗
Add an additional destination NAT rule for internal traffic.
Why it's wrong here
Adding another destination NAT rule would not solve the issue because the return traffic would not follow the same path.
- ✓
Implement a source NAT rule for internal traffic destined to the public IP, translating it to the internal server IP.
Why this is correct
This is the standard NAT hairpin configuration that allows internal users to access the server via its public IP.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.