NGFW-ENGINEER · Question #38
How does a Palo Alto firewall handle traffic between two different security zones?
The correct answer is A. Traffic is denied by default unless a security policy explicitly allows it. Palo Alto Networks firewalls follow a default-deny model for inter-zone traffic. Any traffic flowing between two different security zones is implicitly denied unless a security policy rule explicitly permits it. This is a core principle of the zone-based security architecture…
Question
How does a Palo Alto firewall handle traffic between two different security zones?
Options
- ATraffic is denied by default unless a security policy explicitly allows it
- BTraffic is allowed automatically between zones
- CTraffic is automatically encrypted between zones
- DTraffic between zones is forwarded without inspection
How the community answered
(33 responses)- A94% (31)
- B3% (1)
- C3% (1)
Explanation
Palo Alto Networks firewalls follow a default-deny model for inter-zone traffic. Any traffic flowing between two different security zones is implicitly denied unless a security policy rule explicitly permits it. This is a core principle of the zone-based security architecture: zones segment the network into trust boundaries, and crossing those boundaries requires explicit policy authorization. This is distinct from intra-zone traffic (within the same zone), which is allowed by default. Traffic is neither automatically allowed, encrypted, nor forwarded without inspection when traversing zone boundaries.
Topics
Community Discussion
No community discussion yet for this question.