exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 586 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 586
Topic #: 1
[All PCNSE Questions]

A firewall engineer is managing a Palo Alto Networks NGFW which is not in line of any DHCP traffic.

Which interface mode can the engineer use to generate Enhanced Application logs (EALs) for classifying IoT devices while receiving broadcast DHCP traffic?

  • A. Virtual wire
  • B. Layer 3
  • C. Layer 2
  • D. Tap
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
HappyDay030303
2 days, 15 hours ago
Selected Answer: D
"NGFW is not in line of any DHCP traffic" Virtual Wire can only generate EAL for received traffic
upvoted 1 times
...
corpguy
2 weeks ago
Selected Answer: A
From the links other provided “Virtual Wire: When the firewall has Virtual Wire interfaces with multicast firewalling enabled, it generates Enhanced Application logs (EALs) for broadcast DHCP sessions.”
upvoted 1 times
...
Phoenix2462
2 months, 3 weeks ago
Selected Answer: A
I guess that “in line” in this sentence indicates that unicast DHCP is not received. Only Virtual wire can generate an EAL for broadcast DHCP Traffic. https://docs.paloaltonetworks.com/iot/iot-security-admin/get-started-with-iot-security/firewall-deployment-for-dhcp-visibility/dhcp-data-collection-by-traffic-type
upvoted 1 times
...
apiloran
5 months, 1 week ago
Selected Answer: D
Use Cases for Tap interfaces Evaluations Networks where DHCP is configured on a device “south” of the firewall Monitor networks that don’t naturally traverse the firewall Virtual Wire Interfaces Considerations – You might have to use a Virtual Wire (vWire) interface on the firewall to gain visibility into DHCP traffic that the firewall wouldn’t normally see. Consider the following when using a tap interface in this manner: Ensure the Virtual Wire has multicast firewalling enabled. Ensure the Virtual Wire is in the path for DHCP traffic. This traffic can be either broadcast or unicast. Ensure that a security policy rule allowing DHCP exists and that a proper log-forwarding profile is applied to the rule. Ensure the firewall has the available capacity to process the additional traffic. For guidance on mitigating performance impact, see Use a Virtual Wire Interface for DHCP Visibility.
upvoted 1 times
...
[Removed]
5 months, 3 weeks ago
Answer is "D" "Ensure the Virtual Wire is in the path for DHCP traffic. This traffic can be either broadcast or unicast." Question states that the firewall is not in the path for DHCP, this eliminates "A".
upvoted 1 times
...
unless_mail
6 months, 1 week ago
the engineer can use the Virtual Wire (vWire) interface mode to generate Enhanced Application Logs (EALs) for classifying IoT devices while receiving broadcast DHCP traffic. Here's why: Virtual Wire Interfaces: The text specifies that for Virtual Wire interfaces, multicast firewalling should be enabled. When the DHCP server and the firewall interface are on the same network segment, the firewall sees only broadcast DHCP traffic. Placing the DHCP server behind a Virtual Wire interface enables the firewall to create EALs for this broadcast traffic. This ensures that the firewall can generate the necessary logs even for broadcast DHCP traffic, which is crucial for IoT device classification.
upvoted 1 times
...
unless_mail
6 months, 1 week ago
Selected Answer: A
A. for sure
upvoted 1 times
...
0d2fdfa
6 months, 2 weeks ago
Selected Answer: D
Tap interface does not have to be inline.
upvoted 2 times
...
Mtro
7 months, 1 week ago
Selected Answer: D
Tap Interfaces Considerations – If you use a Tap interface to gain visibility into DHCP traffic that the firewall doesn’t ordinarily see, consider the following: Place the tap “north” of any routed boundary where DHCP is configured. This will ensure that the captured traffic is unicast rather than broadcast. (If the firewall with the Tap interface is in the same broadcast domain as the switch that’s mirroring traffic to it, enable DHCP Broadcast Session at DeviceSetupSession.) Use Cases for Tap interfaces Evaluations Networks where DHCP is configured on a device “south” of the firewall Monitor networks that don’t naturally traverse the firewall
upvoted 2 times
...
hcir
7 months, 2 weeks ago
answer is A. DHCP server, DHCP client and FW on the same broadcast domain means that a VWire interface will only catch the broadcast packets (not the unicast) and will still generate EALs. For a Tap interface to catch the 4 DHCP packets, the switch needs to mirror the traffic.
upvoted 1 times
...
nchunter
7 months, 2 weeks ago
Has anybody recently taken the PCNSE exam? Are there any questions on the exam that are under #300 on the study guide?
upvoted 1 times
...
nchunter
7 months, 2 weeks ago
Has anybody recently taken the PCNSE exam? Are there any questions that are under #300 on the study guide?
upvoted 1 times
...
Loloshikovichev
7 months, 3 weeks ago
Selected Answer: D
As question states, the firewall is not in the traffic path. Tap is the interface that can receive traffic to identification.
upvoted 1 times
...
tonykolo
8 months ago
Selected Answer: D
The question stated "not in line of any DHCP traffic". For Vwire interfaces "Ensure the Virtual Wire is in the path for DHCP traffic. This traffic can be either broadcast or unicast." Tap interface use case "Monitor networks that don’t naturally traverse the firewall". D has to be the right answer.
upvoted 1 times
...
MostafaNawar
8 months ago
Selected Answer: A
A, sure
upvoted 1 times
...
findkeywordcommand
8 months, 1 week ago
Selected Answer: A
"Virtual Wire: When the firewall has Virtual Wire interfaces with multicast firewalling enabled, it generates Enhanced Application logs (EALs) for broadcast DHCP sessions." https://docs.paloaltonetworks.com/iot/iot-security-admin/get-started-with-iot-security/firewall-deployment-for-dhcp-visibility/firewall-deployment-options-for-iot-security
upvoted 1 times
...
jaypogi16
8 months, 2 weeks ago
Selected Answer: A
A. Virtual Wire: When the firewall has Virtual Wire interfaces with multicast firewalling enabled, it generates Enhanced Application logs (EALs) for broadcast DHCP sessions.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago