nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #42

To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical…

The correct answer is B. Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the D. Deploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route. The two architectures that meet all stated requirements are: Answer D for AWS - Deploy Cloud NGFW in a centralized Security VPC and update the existing Transit Gateway routing to steer traffic through it. This leverages the pre-existing Transit Gateway hub-and-spoke topology…

Cloud NGFW Deployment Architectures

Question

To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical data centers. Resources exist on AWS and Azure:

  • The AWS deployment is architected with AWS Transit Gateway, to which

all resources connect

  • The Azure deployment is architected with each application

independently routing traffic The engineer deploying Cloud NGFW in these two cloud environments must account for the following:

  • Minimize changes to the two cloud environments
  • Scale to the demands of the applications while using the least amount

of compute resources

  • Allow the company to unify the Security policies across all protected

areas Which two implementations will meet these requirements? (Choose two.)

Options

  • ADeploy a VM-Series firewall in AWS in each VPC, create an IPSec tunnel between AWS and
  • BDeploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the
  • CDeploy Cloud NGFW for Azure in vWAN, create a vWAN to route all appropriate traffic to the
  • DDeploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route

How the community answered

(56 responses)
  • A
    16% (9)
  • B
    48% (27)
  • C
    36% (20)

Explanation

The two architectures that meet all stated requirements are: Answer D for AWS - Deploy Cloud NGFW in a centralized Security VPC and update the existing Transit Gateway routing to steer traffic through it. This leverages the pre-existing Transit Gateway hub-and-spoke topology, requires minimal changes to individual VPCs, and uses Cloud NGFW's elastic scaling instead of fixed VM-Series compute. Answer B for Azure - Deploy Cloud NGFW within each application vNET and update only the vNET routing tables to direct traffic through it. Since each Azure application already routes independently, inserting Cloud NGFW per-vNET is the least disruptive option. Answer C (vWAN) would require significant architectural changes. Answer A (VM-Series with IPSec) adds unnecessary compute overhead and complexity, contradicting the 'least compute' requirement. Both B and D support unified Panorama-managed security policy.

Topics

#Cloud NGFW Deployment#AWS Networking Integration#Azure Networking Integration#Cloud Security Architecture

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice