ExamGecko
Question list
Search
Search

Question 18 - PCSFE discussion

Report
Export

Which PAN-OS feature allows for automated updates to address objects when VM-Series firewalls are setup as part of an NSX deployment?

A.
Boundary automation
Answers
A.
Boundary automation
B.
Hypervisor integration
Answers
B.
Hypervisor integration
C.
Bootstrapping
Answers
C.
Bootstrapping
D.
Dynamic Address Group
Answers
D.
Dynamic Address Group
Suggested answer: D

Explanation:

Dynamic Address Group is the PAN-OS feature that allows for automated updates to address objects when VM-Series firewalls are setup as part of an NSX deployment. NSX is a software-defined network (SDN) solution that provides network virtualization, automation, and security for cloud-native applications. Dynamic Address Group is an object that represents a group of IP addresses based on criteria such as tags, regions, interfaces, or user-defined attributes. Dynamic Address Group allows Security policies to adapt dynamically to changes in the network topology or workload characteristics without requiring manual updates. When VM-Series firewalls are setup as part of an NSX deployment, they can leverage the NSX tags assigned to virtual machines (VMs) or containers by the NSX manager or controller to populate Dynamic Address Groups and update Security policies accordingly. Boundary automation, Hypervisor integration, and Bootstrapping are not PAN-OS features that allow for automated updates to address objects when VM-Series firewalls are setup as part of an NSX deployment, but they are related concepts that can be used for other purposes.

Reference: Palo Alto Networks Certified Software Firewall Engineer (PCSFE), [Dynamic Address Groups Overview], [Deploy the VM-Series Firewall on VMware NSX]

asked 23/09/2024
Ronald de Groot
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first