exam questions

Exam PCSFE All Questions

View all questions & answers for the PCSFE exam

Exam PCSFE topic 1 question 10 discussion

Actual exam question from Palo Alto Networks's PCSFE
Question #: 10
Topic #: 1
[All PCSFE Questions]

How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?

  • A. By using contracts between endpoint groups that send traffic to the firewall using a shared policy
  • B. Through a virtual machine (VM) monitor domain
  • C. Through a policy-based redirect (PBR)
  • D. By creating an access policy
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Merlin0o
1 week ago
Selected Answer: C
Should be C: The Question is asking how the traffic is send to the PA FW not how to configure it. You may configure it with contracts but the traffic is directed to the PA FW with a PBR. "traffic is sent to the firewall with a policy-based redirect (PBR)" "For east-west traffic, define a bridge domain and subnet in the ACI fabric for the firewall. Configure contracts between EPGs that send traffic to the firewall using a PBR. The PBR forwards traffic to the firewall based on policy containg the firewall’s IP and MAC address." Src: https://docs.paloaltonetworks.com/vm-series/11-1/vm-series-deployment/set-up-a-firewall-in-cisco-aci/palo-alto-firewall-integration-with-cisco-aci-overview
upvoted 1 times
...
kafka1
6 months, 1 week ago
This is one of those purposly missleading questions. "ON" PA FW you use PBR, but here is "TO" PA so I would go for A
upvoted 2 times
...
Zalthoz
6 months, 2 weeks ago
Selected Answer: A
Cisco ACI uses contract to tie in external security appliances
upvoted 1 times
...
hifire
7 months, 1 week ago
Selected Answer: A
Answer A is correct. Cisco ACI is using descriptiv language via UI and API. Contracts can utilize Proxy ARP and PBR as techniques for traffic routing, but it isn't the way to configure. https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-743951.html#Howcontractswork
upvoted 1 times
...
Doobiedoo
1 year ago
Selected Answer: C
https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739971.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago