PSE-STRATADC · Question #20
Which three advantages of the Palo Alto Networks platform architecture are used to enable security orchestration in SDN? (Choose three )
The correct answer is C. integration with leading orchestration platforms: VMware NSX. OpenStack. and Cisco ACI D. Dynamic Address Groups to adapt Security policies dynamically E. VXLAN support for network-layer abstraction. Palo Alto Networks achieves SDN security orchestration through platform-native integrations and dynamic constructs. C is correct because direct integration with VMware NSX, OpenStack, and Cisco ACI allows Palo Alto to participate natively in SDN workflows - policy follows…
Question
Which three advantages of the Palo Alto Networks platform architecture are used to enable security orchestration in SDN? (Choose three )
Options
- Aa full set of APIs enabling programmatic control of policy and configuration
- BNVGRE support for advanced VLAN integration
- Cintegration with leading orchestration platforms: VMware NSX. OpenStack. and Cisco ACI
- DDynamic Address Groups to adapt Security policies dynamically
- EVXLAN support for network-layer abstraction
How the community answered
(27 responses)- A4% (1)
- B11% (3)
- C85% (23)
Explanation
Palo Alto Networks achieves SDN security orchestration through platform-native integrations and dynamic constructs. C is correct because direct integration with VMware NSX, OpenStack, and Cisco ACI allows Palo Alto to participate natively in SDN workflows - policy follows workloads without manual intervention. D is correct because Dynamic Address Groups let firewall rules automatically update when VMs spin up, move, or are tagged differently, which is essential in fluid SDN environments where static IP-based policies quickly become stale. E is correct because VXLAN is the dominant overlay tunneling protocol in modern SDN fabrics, and supporting it lets the Palo Alto platform inspect and enforce policy within those virtual networks at Layer 2 over Layer 3.
A is wrong because while Palo Alto does expose APIs, the question asks specifically about SDN orchestration enablement - APIs are a general management feature, not a defined SDN integration point in this context. B is wrong because NVGRE is a Microsoft-centric protocol that is largely superseded by VXLAN in mainstream SDN deployments and is not a primary integration feature of the Palo Alto SDN story.
Memory tip: Think "CDEployment" - Connect to SDN platforms, Dynamically adapt policies, Extend into VXLAN overlays. If a choice sounds too generic (APIs) or too niche/obsolete (NVGRE), eliminate it.
Topics
Community Discussion
No community discussion yet for this question.