PSE-STRATA-PRO-24 · Question #47
A prospective customer wants to validate an NGFW solution and seeks the advice of a systems engineer (SE) regarding a design to meet the following stated requirements: "We need an NGFW that can…
The correct answer is A. PA-5445 or larger to cover the bandwidth need and the link types; Architect aggregate interface. Option A is correct because the requirement of 72 Gbps with threat prevention, DNS, and sandboxing enabled demands the PA-5445 (or larger) - the PA-5430's threat prevention throughput falls short of 72 Gbps once all security services are active, making it insufficient for this…
Question
A prospective customer wants to validate an NGFW solution and seeks the advice of a systems engineer (SE) regarding a design to meet the following stated requirements:
"We need an NGFW that can handle 72 Gbps inside of our core network. Our core switches only have up to 40 Gbps links available to which new devices can connect. We cannot change the IP address structure of the environment, and we need protection for threat prevention, DNS, and perhaps sandboxing." Which hardware and architecture/design recommendations should the SE make?
Options
- APA-5445 or larger to cover the bandwidth need and the link types; Architect aggregate interface
- BPA-5430 or larger to cover the bandwidth need and the link types; Architect aggregate interface
- CPA-5445 or larger to cover the bandwidth need and the link types; Architect aggregate interface
- DPA-5430 or larger to cover the bandwidth need and the link types; Architect aggregate interface
How the community answered
(23 responses)- A65% (15)
- B4% (1)
- C9% (2)
- D22% (5)
Explanation
Option A is correct because the requirement of 72 Gbps with threat prevention, DNS, and sandboxing enabled demands the PA-5445 (or larger) - the PA-5430's threat prevention throughput falls short of 72 Gbps once all security services are active, making it insufficient for this deployment. The aggregate interface design is essential because the core switches only offer 40 Gbps uplinks; bonding two 40 Gbps links (80 Gbps aggregate) provides the headroom needed to hit 72 Gbps under real traffic conditions. Options B and D fail because the PA-5430 does not meet the throughput requirement when full security inspection (threat prevention + DNS + sandboxing) is factored in - always size based on threat prevention throughput, not raw firewall throughput, since security features reduce effective throughput significantly. Options C appears identical to A as written, which suggests a distractor meant to test attention to the hardware model number - always anchor your choice to the specific model that clears the stated throughput bar.
Memory tip: Use the phrase "Threat Prevention Throughput Trumps Raw Firewall Numbers" - on Palo Alto sizing questions, the throughput figure that matters is the one with all security services enabled, not the base App-ID or firewall number. If the spec sheet's threat prevention number doesn't clear the requirement, go up a model.
Topics
Community Discussion
No community discussion yet for this question.