PSE-SWFW-PRO-24 · Question #73
Which three statements describe common characteristics of Cloud NGFW and VM-Series offerings? (Choose three.)
The correct answer is B. In Azure and AWS, both offerings can be managed by Panorama. D. In Azure, inbound destination NAT configuration also requires source NAT to maintain flow E. In Azure and AWS, internal (east-west) flows can be inspected without any NAT. This question asks about common characteristics of Cloud NGFW (specifically referring to Cloud NGFW for AWS and Azure) and VM-Series firewalls. Option B: This is correct. Panorama is the centralized management platform for Palo Alto Networks firewalls, including both VM-Series…
Question
Which three statements describe common characteristics of Cloud NGFW and VM-Series offerings? (Choose three.)
Options
- AIn Azure, both offerings can be integrated directly into Virtual WAN hubs.
- BIn Azure and AWS, both offerings can be managed by Panorama.
- CIn AWS, both offerings can be managed by AWS Firewall Manager.
- DIn Azure, inbound destination NAT configuration also requires source NAT to maintain flow
- EIn Azure and AWS, internal (east-west) flows can be inspected without any NAT.
How the community answered
(26 responses)- A35% (9)
- B46% (12)
- C19% (5)
Explanation
This question asks about common characteristics of Cloud NGFW (specifically referring to Cloud NGFW for AWS and Azure) and VM-Series firewalls. Option B: This is correct. Panorama is the centralized management platform for Palo Alto Networks firewalls, including both VM-Series and Cloud NGFW deployments in AWS and Azure. Panorama allows for consistent policy management, logging, and reporting across these different deployment models. Option D: This is accurate specifically within the Azure environment. Due to how Azure networking functions, when performing destination NAT (DNAT) for inbound traffic to resources behind a firewall (whether VM-Series or Cloud NGFW), it's typically necessary to also implement source NAT (SNAT) to ensure return traffic follows the same path. This maintains flow symmetry and prevents routing issues. This is an Azure networking characteristic, not specific to the Palo Alto offerings themselves, but it applies to both in Azure. Option E: This is generally true. For traffic within the same Virtual Network (Azure) or VPC (AWS), both VM-Series and Cloud NGFW can inspect traffic without requiring NAT. This is a key advantage for microsegmentation and internal security. The firewalls can act as transparent security gateways for internal traffic.
Topics
Community Discussion
No community discussion yet for this question.