PSE-SWFW-PRO-24 · Question #39
Which three statements describe functionality of NGFW inline placement for Layer 2/3 implementation? (Choose three.)
The correct answer is A. VMs on VMware ESXi hypervisors can be segregated from one another on the network by the B. VMs on VMware ESXi hypervisors can be segregated from each other by the VM-Series NGFW E. A next-generation firewall VLAN interface can function as a Layer 3 interface. Options A and B are correct because VM-Series NGFWs deployed inline on VMware ESXi can enforce security policies between VMs on the same hypervisor, effectively micro-segmenting workloads at the virtual network level - a core use case for inline Layer 2/3 deployment. Option E…
Question
Which three statements describe functionality of NGFW inline placement for Layer 2/3 implementation? (Choose three.)
Options
- AVMs on VMware ESXi hypervisors can be segregated from one another on the network by the
- BVMs on VMware ESXi hypervisors can be segregated from each other by the VM-Series NGFW
- CVM-Series next-generation firewalls cannot be positioned between the physical datacenter
- DVM-Series next-generation firewalls do not support VMware vMotion or guest VM workloads.
- EA next-generation firewall VLAN interface can function as a Layer 3 interface.
How the community answered
(61 responses)- A74% (45)
- C10% (6)
- D16% (10)
Explanation
Options A and B are correct because VM-Series NGFWs deployed inline on VMware ESXi can enforce security policies between VMs on the same hypervisor, effectively micro-segmenting workloads at the virtual network level - a core use case for inline Layer 2/3 deployment. Option E is correct because VLAN subinterfaces on a Palo Alto NGFW can be configured to operate as Layer 3 interfaces, allowing the firewall to route traffic between VLANs while inspecting it, which is fundamental to hybrid Layer 2/3 inline positioning.
C is wrong because VM-Series firewalls can be positioned between physical datacenter components (e.g., between a physical network and a virtual workload tier) - that's a primary deployment scenario.
D is wrong because VM-Series NGFWs do support VMware vMotion; the firewall can follow migrating VMs across hosts, which is essential for maintaining consistent policy in dynamic virtualized environments.
Memory tip: Think of the VM-Series as a "virtual cop at the intersection" - it sits between VMs (A, B), can act as a router via VLAN subinterfaces (E), can span physical/virtual boundaries (eliminating C), and moves with your VMs via vMotion (eliminating D). Anything suggesting the VM-Series can't do something it's specifically designed for is a red flag.
Topics
Community Discussion
No community discussion yet for this question.