Courseiva
easyMultiple ChoiceObjective-mapped

PCNSA Practice Question: A company uses destination NAT to translate a…

A company uses destination NAT to translate a public IP to an internal server. They need to ensure that traffic sourced from the internal network to the public IP is also translated correctly. What is the best practice to achieve this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a source NAT rule for internal traffic destined to the public IP, translating it to the internal server IP.

When internal users access the public IP that is destination NATed to an internal server, the traffic must be source NATed to ensure symmetric routing. Without source NAT, the server sees the source as the internal client IP and sends the response directly to the client, causing asymmetric routing and connection failures. Implementing a source NAT rule for internal traffic destined to the public IP (hairpin NAT) ensures the firewall translates the source to its own internal IP, so the response goes back through the firewall. Option A is incorrect because disabling NAT on the loopback interface does not address the issue. Option B is incorrect because policy-based forwarding (PBF) is used for routing decisions, not NAT. Option C is incorrect because an additional destination NAT rule would not change the source address; source NAT is required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable NAT on the internal zone's loopback interface.

    Why it's wrong here

    Loopback interfaces are not involved in NAT hairpinning for this scenario.

  • Configure a policy-based forwarding rule to redirect internal traffic.

    Why it's wrong here

    Policy-based forwarding is used for routing decisions, not for NAT hairpinning.

  • Add an additional destination NAT rule for internal traffic.

    Why it's wrong here

    Adding another destination NAT rule would not solve the issue because the return traffic would not follow the same path.

  • Implement a source NAT rule for internal traffic destined to the public IP, translating it to the internal server IP.

    Why this is correct

    This is the standard NAT hairpin configuration that allows internal users to access the server via its public IP.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.