nerdexam
Palo_Alto_Networks

PCNSE · Question #484

A prospect is eager to conduct a Security Lifecycle Review (SLR) with the aid of the Palo Alto Networks NGFW. Which interface type is best suited to provide the raw data for an SLR from the network…

The correct answer is C. Tap. A Tap interface is the best choice for a Security Lifecycle Review (SLR) because it is completely passive and non-invasive. The firewall receives a copy of network traffic via a SPAN or mirror port on a switch, analyzes it, and generates the SLR report without being inline in…

Submitted by kevin_r· Apr 18, 2026Deploy and Configure

Question

A prospect is eager to conduct a Security Lifecycle Review (SLR) with the aid of the Palo Alto Networks NGFW. Which interface type is best suited to provide the raw data for an SLR from the network in a way that is minimally invasive?

Options

  • ALayer 3
  • BVirtual Wire
  • CTap
  • DLayer 2

How the community answered

(42 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    88% (37)
  • D
    2% (1)

Explanation

A Tap interface is the best choice for a Security Lifecycle Review (SLR) because it is completely passive and non-invasive. The firewall receives a copy of network traffic via a SPAN or mirror port on a switch, analyzes it, and generates the SLR report without being inline in the traffic path. This means there is zero risk of disrupting production traffic. Layer 2 and Layer 3 interfaces require the firewall to be inserted inline into the network, which requires topology changes and carries risk. Virtual Wire is also inline. Only the Tap interface allows passive traffic capture with no network impact, making it ideal for an assessment or proof-of-concept engagement.

Topics

#NGFW Interface Modes#Tap Mode#Security Lifecycle Review (SLR)#Passive Network Monitoring

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice