nerdexam
Palo_Alto_Networks

PSE-STRATADC · Question #54

How do Palo Alto Networks NGFWs integrate with an ACI architecture?

The correct answer is B. Traffic can be automatically redirected using static Address objects. Option B is correct because Palo Alto Networks NGFWs integrate with Cisco ACI (Application Centric Infrastructure) through ACI's Policy-Based Redirection (PBR) and service graph templates, which automatically steer traffic to the NGFW. On the firewall side, static Address…

Software-Defined Networking Integration

Question

How do Palo Alto Networks NGFWs integrate with an ACI architecture?

Options

  • ASDN code hooks can help to detonate malicious file samples designed to detect virtual
  • BTraffic can be automatically redirected using static Address objects.
  • CVXLAN or NVGRE traffic is terminated and inspected for translation to VLANs.
  • DControllers can program firewalls using a REST-based API.

How the community answered

(27 responses)
  • A
    15% (4)
  • B
    74% (20)
  • C
    4% (1)
  • D
    7% (2)

Explanation

Option B is correct because Palo Alto Networks NGFWs integrate with Cisco ACI (Application Centric Infrastructure) through ACI's Policy-Based Redirection (PBR) and service graph templates, which automatically steer traffic to the NGFW. On the firewall side, static Address objects define the endpoint groups and subnets that match this redirected traffic, allowing security policies to be applied consistently as ACI dynamically routes flows through the firewall.

Why the distractors are wrong:

  • A describes sandbox/WildFire behavior for detecting virtual environment-aware malware - a threat prevention feature, not an ACI integration mechanism.
  • C describes VXLAN/NVGRE tunnel termination, which relates to overlay network inspection capabilities, not the specific way ACI integrates with an NGFW (ACI uses VXLAN internally, but that's not the integration point).
  • D is tempting because the Palo Alto API exists and APIC can communicate via REST, but the defining integration method is traffic redirection, not the controller directly programming firewall rules via REST API.

Memory tip: Think of ACI as a traffic cop that automatically points cars (traffic) to the NGFW checkpoint, and the firewall's Address objects are the pre-painted lane markings telling it which cars to inspect. ACI handles the "redirect," Palo Alto handles the "inspect."

Topics

#ACI integration#REST API#SDN#automated policy redirect

Community Discussion

No community discussion yet for this question.

Full PSE-STRATADC Practice