PSE-SWFW-PRO-24 · Question #58
A customer with multiple virtual private clouds (VPCs) in Amazon Web Services (AWS) protected by the cloud-native firewall experiences a cloud breach. As a result, malware spreads quickly across the…
The correct answer is D. Implement a Cloud NGFW for each VPC. The customer's AWS environment, with multiple VPCs protected by a cloud-native firewall, experienced a breach due to malware spreading across VPCs, indicating inadequate segmentation and visibility. The Palo Alto Networks Systems Engineer Professional - Software Firewall…
Question
A customer with multiple virtual private clouds (VPCs) in Amazon Web Services (AWS) protected by the cloud-native firewall experiences a cloud breach. As a result, malware spreads quickly across the VPCs, infecting several workloads. Which minimum solution should be proposed to prevent similar incidents in the future?
Options
- APurchase a software credit pool for flexible Cloud NGFW deployment across the VPCs.
- BDeploy a single Cloud NGFW.
- CSubscribe to Palo Alto Networks Advanced Threat Protection for the cloud-native firewall.
- DImplement a Cloud NGFW for each VPC.
How the community answered
(35 responses)- A20% (7)
- B14% (5)
- C6% (2)
- D60% (21)
Explanation
The customer's AWS environment, with multiple VPCs protected by a cloud-native firewall, experienced a breach due to malware spreading across VPCs, indicating inadequate segmentation and visibility. The Palo Alto Networks Systems Engineer Professional - Software Firewall documentation provides guidance on securing multi-VPC AWS environments with Cloud NGFW, focusing on preventing lateral movement and enhancing threat prevention. Option D: Deploying a Cloud NGFW instance in each VPC ensures localized traffic inspection, segmentation, and control, preventing malware from spreading laterally across VPCs. Cloud NGFW for AWS supports a distributed deployment model, allowing each VPC to have its own firewall instance integrated with AWS services (e.g., VPC routing, Security Groups) to enforce policies, block threats, and maintain visibility.
Topics
Community Discussion
No community discussion yet for this question.