nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #16

An organization runs multiple Kubernetes clusters both on-premises and in public clouds (AWS, Azure, GCP). They want to deploy the Palo Alto Networks CN-Series NGFW to secure east-west traffic within

Sign in or unlock NGFW-ENGINEER to reveal the answer and full explanation for question #16. The question stem and answer options stay visible for context.

CN-Series Deployment and Management in Kubernetes

Question

An organization runs multiple Kubernetes clusters both on-premises and in public clouds (AWS, Azure, GCP). They want to deploy the Palo Alto Networks CN-Series NGFW to secure east-west traffic within each cluster, maintain consistent Security policies across all environments, and dynamically scale as containerized workloads spin up or down. They also plan to use a centralized Panorama instance for policy management and visibility. Which approach meets these requirements?

Options

  • AInstall standalone CN-Series instances in each cluster with local configuration only. Export daily
  • BConfigure the CN-Series only in public cloud clusters, and rely on Kubernetes Network Policies
  • CUse Kubernetes-native deployment tools (e.g., Helm) to deploy CN-Series in each cluster,
  • DDeploy a single CN-Series firewall in the on-premises data center to process traffic for all clusters,

Unlock NGFW-ENGINEER to see the answer

You've previewed enough free NGFW-ENGINEER questions. Unlock NGFW-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CN-Series Deployment#Kubernetes Security#Panorama Integration#Multi-Cloud Security
Full NGFW-ENGINEER Practice