ExamGecko
Question list
Search
Search

Related questions











Question 338 - PCNSE discussion

Report
Export

A network security engineer needs to enable Zone Protection in an environment that makes use of Cisco TrustSec Layer 2 protections

What should the engineer configure within a Zone Protection profile to ensure that the TrustSec packets are identified and actions are taken upon them?

A.
TCP Fast Open in the Strip TCP options
Answers
A.
TCP Fast Open in the Strip TCP options
B.
Ethernet SGT Protection
Answers
B.
Ethernet SGT Protection
C.
Stream ID in the IP Option Drop options
Answers
C.
Stream ID in the IP Option Drop options
D.
Record Route in IP Option Drop options
Answers
D.
Record Route in IP Option Drop options
Suggested answer: B

Explanation:

Cisco TrustSec technology uses Security Group Tags (SGTs) to enforce access controls on Layer 2 traffic. When implementing Zone Protection on a Palo Alto Networks firewall in an environment with Cisco TrustSec, you should configure Ethernet SGT Protection. This setting ensures that the firewall can recognize SGTs in Ethernet frames and apply the appropriate actions based on the configured policies. The use of Ethernet SGT Protection in conjunction with TrustSec is covered in advanced firewall configuration documentation and in interoperability guides between Palo Alto Networks and Cisco systems.

asked 23/09/2024
Miles Greenyer
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first