Courseiva

PCNSE Deploy and Configure Firewalls Practice Question

An engineer is configuring a Palo Alto Networks firewall to perform source NAT for outbound traffic from the 10.1.1.0/24 subnet to the internet. The firewall has an external interface with IP 203.0.113.5/24. The requirement is to translate all outbound traffic to the external interface's IP address and ensure that return traffic is correctly routed back to the internal hosts. Which NAT policy configuration achieves this?

⚠ Common exam trap

The trap here is thinking that a separate inbound NAT rule or bi-directional option is needed for return traffic, when the stateful firewall automatically manages it for source NAT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5'. No destination translation.

For source NAT, the correct configuration is a NAT rule that translates the source IP of outbound packets from the internal subnet to the external interface IP. The firewall automatically handles return traffic by reversing the translation for established sessions, so no additional rules are needed. This provides hide NAT, allowing multiple internal hosts to share a single public IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and configure a separate NAT rule for inbound traffic from untrust to trust with destination address '203.0.113.5' and translated destination '10.1.1.0/24'.

    Why it's wrong here

    A separate inbound NAT rule is not required for source NAT. The firewall's stateful inspection automatically allows return traffic for established sessions and reverses the translation. Creating an inbound rule would be for destination NAT (port forwarding) and is not needed here. This would also expose internal hosts to unsolicited inbound connections, which is a security risk.

  • ✓

    Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5'. No destination translation.

    Why this is correct

    This rule translates the source IP of outbound packets from 10.1.1.0/24 to the external interface IP 203.0.113.5. The original packet zones identify traffic from trust to untrust. The firewall automatically handles return traffic by reversing the translation for established sessions. This is the standard source NAT configuration for hide NAT.

  • ✗

    Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and set the destination translation to the original destination. This ensures return traffic is routed correctly.

    Why it's wrong here

    Destination translation is not needed for source NAT. Setting destination translation to the original destination would have no effect but could cause confusion. The return traffic is handled by the firewall's session table, which reverses the source translation. Adding destination translation is unnecessary and may lead to misconfiguration.

  • ✗

    Create a NAT rule with original packet source zone 'trust', destination zone 'untrust', source address '10.1.1.0/24', and translated packet source address '203.0.113.5', and enable 'Bi-directional' option to allow return traffic.

    Why it's wrong here

    The 'Bi-directional' option is used for destination NAT to allow return traffic to be translated back, but for source NAT, it is not needed. Enabling it can cause unexpected behavior because it also creates a reverse rule. For simple source NAT, the firewall automatically handles return traffic without bi-directional. This option is typically used when both source and destination NAT are required.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.