nerdexam
Palo_Alto_Networks

PSE-SWFW-PRO-24 · Question #18

Per reference architecture, which default PAN-OS configuration should be overridden to make VM- Series firewall deployments in the public cloud more secure?

The correct answer is C. Interzone-default rule action and logging. The default interzone rule in PAN-OS is typically set to "deny." While this is generally secure, the logging is not enabled by default. In public cloud deployments, enabling logging for the interzone- default rule is crucial for visibility and troubleshooting. Overriding the…

Security Policy Configuration and Best Practices

Question

Per reference architecture, which default PAN-OS configuration should be overridden to make VM- Series firewall deployments in the public cloud more secure?

Options

  • AIntrazone-default rule action and logging
  • BInterzone-default rule service
  • CInterzone-default rule action and logging
  • DIntrazone-default rule service

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    10% (3)
  • C
    83% (24)
  • D
    3% (1)

Explanation

The default interzone rule in PAN-OS is typically set to "deny." While this is generally secure, the logging is not enabled by default. In public cloud deployments, enabling logging for the interzone- default rule is crucial for visibility and troubleshooting. Overriding the action of the interzone- default rule is generally not recommended (unless you have very specific requirements). The default "deny" action is a core security principle. However, overriding the logging is essential. By enabling logging, you gain visibility into any traffic that is denied by this default rule, which is vital for security auditing and troubleshooting connectivity issues.

Topics

#interzone-default rule#PAN-OS security defaults#public cloud security#logging configuration

Community Discussion

No community discussion yet for this question.

Full PSE-SWFW-PRO-24 Practice