exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 378 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 378
Topic #: 1
[All PCNSE Questions]

A firewall administrator wants to have visibility on one segment of the company network. The traffic on the segment is routed on the Backbone switch. The administrator is planning to apply Security rules on segment X after getting the visibility.
There is already a PAN-OS firewall used in L3 mode as an internet gateway, and there are enough system resources to get extra traffic on the firewall. The administrator needs to complete this operation with minimum service interruptions and without making any IP changes.
What is the best option for the administrator to take?

  • A. Configure the TAP interface for segment X on the firewall
  • B. Configure a Layer 3 interface for segment X on the firewall.
  • C. Configure vwire interfaces for segment X on the firewall.
  • D. Configure a new vsys for segment X on the firewall.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
scally
Highly Voted 2 years, 4 months ago
Selected Answer: C
The correct answer is C. As it specifically states in the question that security rules will be applied, VWire is the only method that allows this without making any IP address changes.
upvoted 13 times
TheIronSheik
1 year, 11 months ago
"security rules will be applied AFTER visibility". The word "after" makes me wonder.
upvoted 2 times
...
...
nose999
Highly Voted 2 years, 4 months ago
Selected Answer: C
Maybe C as security rules will also be applied later
upvoted 7 times
...
CarlosDV06
Most Recent 1 month, 2 weeks ago
Selected Answer: C
Well, he definitely could use A to monitor the traffic, but you would have to reconfigure the fw to use the vwire to apply security changes. Still you can have the vwire and an initial allow rule for all of the X segment traffic and there you get to have your visibility without disrupting the network.
upvoted 1 times
...
Alquicerm
3 months, 2 weeks ago
Selected Answer: C
Because of security rules creation it needs to be VWIRE. TAP will gain visibility but you will not be able to create security rules.
upvoted 1 times
...
0d2fdfa
7 months ago
Selected Answer: A
security rules will be applied but this is only to monitor the traffic. The least intrusive way is TAP mode.
upvoted 1 times
...
scanossa
10 months, 2 weeks ago
Selected Answer: C
It needs to apply security policies which TAP can not to so it's C.
upvoted 1 times
...
Marshpillowz
11 months, 2 weeks ago
Selected Answer: C
I think C
upvoted 1 times
...
Metgatz
1 year ago
C - The administrator is planning to apply Security rules on segment X after getting the visibility.
upvoted 1 times
...
34f7d3a
1 year, 1 month ago
Selected Answer: A
the answer is A - A firewall administrator wants to have visibility on one segment of the company network. Guys why don’t you read with understanding?
upvoted 2 times
Pacheco
11 months, 1 week ago
You should really take your own advice. It clearly says "The administrator is planning to apply Security rules on segment X after getting the visibility". Traffic from tap interfaces is not subject to policy enforcement, you just get a copy of it and that's it.
upvoted 3 times
...
...
franko_72
1 year, 1 month ago
In the exam, July 2023.
upvoted 2 times
...
dorf05
1 year, 2 months ago
Selected Answer: C
Key word== The administrator is planning to apply Security rules on segment X after getting the visibility..... and you cannot apply security rules on segment X using a TAP mode.
upvoted 3 times
...
piipo
1 year, 2 months ago
Selected Answer: C
apply Security rules
upvoted 2 times
...
dgonz
1 year, 4 months ago
Selected Answer: A
A - Tap admin just wants to have traffic visibility.
upvoted 3 times
Pacheco
11 months, 1 week ago
Nope. They also want to apply sec policies to it. "The administrator is planning to apply Security rules on segment X after getting the visibility"
upvoted 1 times
...
...
electro165
1 year, 4 months ago
Selected Answer: A
TAP Interface: A TAP interface allows you to monitor network traffic without disrupting the existing traffic flow. It operates in a passive mode, where it copies traffic for analysis without impacting the original traffic. This means you can gain visibility into segment X without changing the routing or IP configurations. Minimum Service Interruptions: Since the TAP interface is passive and does not actively participate in routing or affecting traffic, it minimizes service interruptions. It won't introduce any routing changes or disruptions to segment X. No IP Changes: The administrator wants to avoid making IP changes, and configuring a TAP interface allows you to do just that. It won't require any IP address changes or reconfiguration of the existing network.
upvoted 1 times
Pacheco
11 months, 1 week ago
Nope. They also want to apply sec policies to it. "The administrator is planning to apply Security rules on segment X after getting the visibility"
upvoted 2 times
...
...
ChiaPet75
1 year, 4 months ago
I'm on the "C" team. At first I thought the Admin could just "TAP" the backbone switch for visibility, but since the goal is to apply Security rules on the segment that is being monitored, vWire makes the most sense.
upvoted 1 times
...
sov4
1 year, 5 months ago
Selected Answer: C
Gotta be C. The traffic isnt on the firewall yet and so a tap wont help. Only a virtual-wire will allow for visibility, security policy, no IP changes, and low down-time.
upvoted 2 times
...
ruben_castro81
1 year, 6 months ago
Selected Answer: A
The key word is "after". This question mention: "The administrator is planning to apply Security rules on segment X AFTER getting the visibility"... I think that TAP is the best option
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago