PSE-SWFW-PRO-24 · Question #85
What are three components of Cloud NGFW for AWS? (Choose three.)
The correct answer is A. Cloud NGFW Resource B. Local or Global Rulestacks C. Cloud NGFW Inspector. Cloud NGFW for AWS is a Next-Generation Firewall as a Service. Its key components work together to provide comprehensive network security. Option A: This represents the actual deployed firewall instance within your AWS environment. It's the core processing engine that inspects…
Question
What are three components of Cloud NGFW for AWS? (Choose three.)
Options
- ACloud NGFW Resource
- BLocal or Global Rulestacks
- CCloud NGFW Inspector
- DAmazon S3 bucket
- ECloud NGFW Tenant
How the community answered
(30 responses)- A93% (28)
- D3% (1)
- E3% (1)
Explanation
Cloud NGFW for AWS is a Next-Generation Firewall as a Service. Its key components work together to provide comprehensive network security. Option A: This represents the actual deployed firewall instance within your AWS environment. It's the core processing engine that inspects and secures network traffic. The Cloud NGFW resource is deployed in a VPC and associated with subnets, enabling traffic inspection between VPCs, subnets, and to/from the internet. Option B: These define the security policies that govern traffic inspection. Rulestacks contain rules that match traffic based on various criteria (e.g., source/destination IP, port, application) and specify the action to take (e.g., allow, deny, inspect). Local Rulestacks are specific to a single Cloud NGFW resource, while Global Rulestacks can be shared across multiple Cloud NGFW resources for consistent policy enforcement. Option C: The Cloud NGFW Inspector is the core component performing the deep packet inspection and applying security policies. It resides within the Cloud NGFW Resource and analyzes network traffic based on the configured rulestacks. It provides advanced threat prevention capabilities, including intrusion prevention (IPS), malware detection, and URL filtering.
Topics
Community Discussion
No community discussion yet for this question.