NGFW-ENGINEER · Question #42
To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical…
The correct answer is B. Deploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the D. Deploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route. The two architectures that meet all stated requirements are: Answer D for AWS - Deploy Cloud NGFW in a centralized Security VPC and update the existing Transit Gateway routing to steer traffic through it. This leverages the pre-existing Transit Gateway hub-and-spoke topology…
Question
To maintain security efficacy of its public cloud resources by using native tools, a company purchases Cloud NGFW credits to replicate the Panorama, PA-Series, and VM-Series devices used in physical data centers. Resources exist on AWS and Azure:
- The AWS deployment is architected with AWS Transit Gateway, to which
all resources connect
- The Azure deployment is architected with each application
independently routing traffic The engineer deploying Cloud NGFW in these two cloud environments must account for the following:
- Minimize changes to the two cloud environments
- Scale to the demands of the applications while using the least amount
of compute resources
- Allow the company to unify the Security policies across all protected
areas Which two implementations will meet these requirements? (Choose two.)
Options
- ADeploy a VM-Series firewall in AWS in each VPC, create an IPSec tunnel between AWS and
- BDeploy Cloud NGFW for Azure in vNET/s, update the vNET/s routing to path traffic through the
- CDeploy Cloud NGFW for Azure in vWAN, create a vWAN to route all appropriate traffic to the
- DDeploy Cloud NGFW for AWS in a centralized Security VPC, update the Transit Gateway to route
How the community answered
(56 responses)- A16% (9)
- B48% (27)
- C36% (20)
Explanation
The two architectures that meet all stated requirements are: Answer D for AWS - Deploy Cloud NGFW in a centralized Security VPC and update the existing Transit Gateway routing to steer traffic through it. This leverages the pre-existing Transit Gateway hub-and-spoke topology, requires minimal changes to individual VPCs, and uses Cloud NGFW's elastic scaling instead of fixed VM-Series compute. Answer B for Azure - Deploy Cloud NGFW within each application vNET and update only the vNET routing tables to direct traffic through it. Since each Azure application already routes independently, inserting Cloud NGFW per-vNET is the least disruptive option. Answer C (vWAN) would require significant architectural changes. Answer A (VM-Series with IPSec) adds unnecessary compute overhead and complexity, contradicting the 'least compute' requirement. Both B and D support unified Panorama-managed security policy.
Topics
Community Discussion
No community discussion yet for this question.