PSE-SWFW-PRO-24 · Question #18
Per reference architecture, which default PAN-OS configuration should be overridden to make VM- Series firewall deployments in the public cloud more secure?
The correct answer is C. Interzone-default rule action and logging. The default interzone rule in PAN-OS is typically set to "deny." While this is generally secure, the logging is not enabled by default. In public cloud deployments, enabling logging for the interzone- default rule is crucial for visibility and troubleshooting. Overriding the…
Question
Per reference architecture, which default PAN-OS configuration should be overridden to make VM- Series firewall deployments in the public cloud more secure?
Options
- AIntrazone-default rule action and logging
- BInterzone-default rule service
- CInterzone-default rule action and logging
- DIntrazone-default rule service
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C83% (24)
- D3% (1)
Explanation
The default interzone rule in PAN-OS is typically set to "deny." While this is generally secure, the logging is not enabled by default. In public cloud deployments, enabling logging for the interzone- default rule is crucial for visibility and troubleshooting. Overriding the action of the interzone- default rule is generally not recommended (unless you have very specific requirements). The default "deny" action is a core security principle. However, overriding the logging is essential. By enabling logging, you gain visibility into any traffic that is denied by this default rule, which is vital for security auditing and troubleshooting connectivity issues.
Topics
Community Discussion
No community discussion yet for this question.