PCNSA · Question #101
Which data flow direction is protected in a zero trust firewall deployment that is not protected in a perimeter-only firewall deployment?
The correct answer is D. east west. In a Zero Trust firewall deployment, "east-west" traffic, which refers to communication between internal systems, is protected, unlike in a traditional perimeter-only firewall deployment that primarily secures north-south traffic.
Question
Which data flow direction is protected in a zero trust firewall deployment that is not protected in a perimeter-only firewall deployment?
Options
- Aoutbound
- Bnorth south
- Cinbound
- Deast west
How the community answered
(64 responses)- A3% (2)
- B2% (1)
- C5% (3)
- D91% (58)
Why each option
In a Zero Trust firewall deployment, "east-west" traffic, which refers to communication between internal systems, is protected, unlike in a traditional perimeter-only firewall deployment that primarily secures north-south traffic.
Outbound traffic is protected by both perimeter and Zero Trust firewalls, as it crosses the network boundary.
North-south traffic is the primary focus of protection for traditional perimeter firewalls, so it's already protected in that model.
Inbound traffic is protected by both perimeter and Zero Trust firewalls, as it crosses the network boundary from external sources.
A Zero Trust model assumes compromise is possible internally and applies security policies to "east-west" traffic, which flows laterally between devices and applications *within* the internal network, thus providing protection against lateral movement, a capability not inherently present in perimeter-only deployments.
Concept tested: Zero Trust Architecture vs. Perimeter Security, Traffic Flow
Source: https://docs.paloaltonetworks.com/zero-trust/what-is-zero-trust/zero-trust-architecture/zero-trust-principles
Topics
Community Discussion
No community discussion yet for this question.