nerdexam
Palo_Alto_Networks

PCNSE · Question #418

An organization's administrator has the funds available to purchase more firewalls to increase the organization's security posture. The partner SE recommends placing the firewalls as close as…

The correct answer is B. Yes. Firewalls are session-based, so they do not scale to millions of CPS. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/firewall-placement-for-dos-protection The firewall is a session-based device that isn’t designed to scale to millions of connections-per- second (CPS) to defend against…

Submitted by katya_ua· Apr 18, 2026Plan

Question

An organization's administrator has the funds available to purchase more firewalls to increase the organization's security posture. The partner SE recommends placing the firewalls as close as possible to the resources that they protect. Is the SE's advice correct, and why or why not?

Options

  • ANo. Firewalls provide new defense and resilience to prevent attackers at every stage of the
  • BYes. Firewalls are session-based, so they do not scale to millions of CPS.
  • CNo. Placing firewalls in front of perimeter DDoS devices provides greater protection for sensitive
  • DYes. Zone Protection profiles can be tailored to the resources that they protect via the

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    85% (39)
  • C
    9% (4)
  • D
    2% (1)

Explanation

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/firewall-placement-for-dos-protection The firewall is a session-based device that isn’t designed to scale to millions of connections-per- second (CPS) to defend against large volumetric DoS attacks.

Topics

#Firewall Deployment#Network Segmentation#Firewall Performance#Security Architecture

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice