nerdexam
Palo_Alto_Networks

PCNSA · Question #72

Which data flow direction is protected in a zero-trust firewall deployment that is not protected in a perimeter-only firewall deployment?

The correct answer is D. east-west. A perimeter-only (traditional) firewall deployment only inspects north-south traffic - traffic entering and leaving the network from external sources. East-west traffic refers to lateral traffic moving between internal systems, servers, or segments within the same network. In a…

Submitted by renata2k· Apr 18, 2026Securing Traffic

Question

Which data flow direction is protected in a zero-trust firewall deployment that is not protected in a perimeter-only firewall deployment?

Options

  • Anorth-south
  • Binbound
  • Coutbound
  • Deast-west

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    93% (25)

Explanation

A perimeter-only (traditional) firewall deployment only inspects north-south traffic - traffic entering and leaving the network from external sources. East-west traffic refers to lateral traffic moving between internal systems, servers, or segments within the same network. In a perimeter-only model, this internal traffic is implicitly trusted and never inspected. A Zero Trust deployment treats all traffic as untrusted, placing firewalls and inspection capabilities between internal segments to monitor and control east-west traffic, preventing attackers from moving laterally once inside the network.

Topics

#Zero Trust#Network Segmentation#Traffic Flow#Firewall Deployment

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice