PSE-SWFW-PRO-24 · Question #31
Which three Cloud NGFW management tasks are inherently performed by the service within AWS and Azure? (Choose three.)
The correct answer is A. Horizontally scaling out to meet increased traffic demand B. Installing new content (applications and threats) C. Installing new PAN-OS software updates. The question asks about Cloud NGFW management tasks performed inherently by the service within AWS and Azure. This means we are looking for tasks that are automated and handled by the Cloud NGFW service itself, not by the customer. Option A: This is a core feature of…
Question
Which three Cloud NGFW management tasks are inherently performed by the service within AWS and Azure? (Choose three.)
Options
- AHorizontally scaling out to meet increased traffic demand
- BInstalling new content (applications and threats)
- CInstalling new PAN-OS software updates
- DBlocking high-risk S2C threats in accordance with SOC2 compliance
- EDecrypting high-risk SSL traffic
How the community answered
(49 responses)- A88% (43)
- D4% (2)
- E8% (4)
Explanation
The question asks about Cloud NGFW management tasks performed inherently by the service within AWS and Azure. This means we are looking for tasks that are automated and handled by the Cloud NGFW service itself, not by the customer. Option A: This is a core feature of cloud-native services. Cloud NGFW is designed to automatically scale its resources (compute, memory, etc.) based on traffic volume. This eliminates the need for manual intervention by the customer to provision or de-provision resources. This aligns with the general principles of cloud elasticity and autoscaling, which are fundamental to cloud-native services like Cloud NGFW. While explicit public documentation detailing the exact scaling mechanism is limited, it's a standard practice for cloud- based services and is implied in the general description of Cloud NGFW as a managed service. Option B: Palo Alto Networks maintains the threat intelligence and application databases for Cloud NGFW. This means that updates to these databases, which are crucial for identifying and blocking threats, are automatically pushed to the service by Palo Alto Networks. Customers do not need to manually download or install these updates. This is consistent with how Palo Alto Networks manages its other security services, such as Threat Prevention and WildFire, where content updates are delivered automatically. Option C: Just like content updates, PAN-OS software updates are also managed by Palo Alto Networks for Cloud NGFW. This ensures that the service is always running the latest and most secure version of the operating system. This removes the operational burden of managing software updates from the customer. This is a key advantage of a managed service.
Topics
Community Discussion
No community discussion yet for this question.