ExamGecko
Question list
Search
Search

Related questions











Question 264 - PCNSE discussion

Report
Export

A firewall administrator wants to have visibility on one segment of the company network. The traffic on the segment is routed on the Backbone switch. The administrator is planning to apply Security rules on segment X after getting the visibility.

There is already a PAN-OS firewall used in L3 mode as an internet gateway, and there are enough system resources to get extra traffic on the firewall. The administrator needs to complete this operation with minimum service interruptions and without making any IP changes.

What is the best option for the administrator to take?

A.
Configure the TAP interface for segment X on the firewall.
Answers
A.
Configure the TAP interface for segment X on the firewall.
B.
Configure vwire interfaces for segment X on the firewall.
Answers
B.
Configure vwire interfaces for segment X on the firewall.
C.
Configure a Layer 3 interface for segment X on the firewall.
Answers
C.
Configure a Layer 3 interface for segment X on the firewall.
D.
Configure a new vsys for segment X on the firewall.
Answers
D.
Configure a new vsys for segment X on the firewall.
Suggested answer: A

Explanation:

A TAP interface is a dedicated interface on the firewall that can be connected to a switch SPAN or mirror port to passively monitor traffic flows across a network. A TAP interface provides application visibility and threat detection without being in the flow of network traffic. A TAP interface does not require any IP changes or service interruptions on the network segment1. Option B is incorrect because vwire interfaces are used to create virtual wires that transparently connect two network segments. Vwire interfaces require physical cabling changes and may cause service interruptions on the network segment2. Option C is incorrect because a Layer 3 interface is used to route traffic between different subnets. A Layer 3 interface requires IP changes and may cause service interruptions on the network segment2. Option D is incorrect because a new vsys is used to create a virtual system that can have its own set of policies and objects. A new vsys does not provide visibility or security for a specific network segment3.

asked 23/09/2024
Shafqat Balouch
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first