NETSEC-PRO · Question #36
Which of the following are considered best practices for network hardening on Palo Alto firewalls? (Choose two)
The correct answer is B. Use User-ID and Device-ID-based policies D. Segment networks using zones. Use User-ID and Device-ID-based policies: This approach enhances security by allowing granular policy enforcement based on authenticated user identity and device information, rather than just IP addresses, improving control and reducing attack surfaces. Segment networks using zon
Question
Which of the following are considered best practices for network hardening on Palo Alto firewalls? (Choose two)
Options
- AEnable unused administrative interfaces
- BUse User-ID and Device-ID-based policies
- CDisable logging
- DSegment networks using zones
How the community answered
(28 responses)- A18% (5)
- B75% (21)
- C7% (2)
Explanation
Use User-ID and Device-ID-based policies: This approach enhances security by allowing granular policy enforcement based on authenticated user identity and device information, rather than just IP addresses, improving control and reducing attack surfaces. Segment networks using zones: Network segmentation by creating zones helps isolate different network areas, limits lateral movement of threats, and enables precise policy enforcement between network segments, which is fundamental for robust security posture.
Topics
Community Discussion
No community discussion yet for this question.