exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 113 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 113
Topic #: 1
[All PCNSE Questions]

A company wants to install a NGFW firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and to assign untagged (native) traffic to its own zone.
Which option differentiates multiple VLANs into separate zones?

  • A. Create V-Wire objects with two V-Wire interfaces and define a range of ג€0-4096ג€ in the ג€Tag Allowedג€ field of the V-Wire object.
  • B. Create V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the ג€Tag Allowedג€ field of the V-Wire object. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each interface/subinterface to a unique zone.
  • C. Create Layer 3 subinterfaces that are each assigned to a single VLAN ID and a common virtual router. The physical Layer 3 interface would handle untagged traffic. Assign each interface/subinterface to a unique zone. Do not assign any interface an IP address.
  • D. Create VLAN objects for each VLAN and assign VLAN interfaces matching each VLAN ID. Repeat for every additional VLAN and use a VLAN ID of 0 for untagged traffic. Assign each interface/subinterface to a unique zone.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChiaPet75
Highly Voted 4 years, 4 months ago
Correct: B The question says that the firewall was installed on a "trunk" link between to core switches. This mean Layer-3 is not usable in this situation. "Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic. You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet." https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/vlan-tagged-traffic.html
upvoted 22 times
...
sapahsaph
Highly Voted 3 years, 11 months ago
correct answer is B Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic. You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet.
upvoted 7 times
...
Marshpillowz
Most Recent 9 months, 2 weeks ago
Selected Answer: B
B is correct
upvoted 1 times
...
lol12
1 year, 11 months ago
Selected Answer: B
Question is asking about traffic between two core switches... and this suggests VWire. In addition the requirement is for each VLAN to have it's own zone.
upvoted 2 times
...
TAKUM1y
2 years, 1 month ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces
upvoted 2 times
...
taherborgan
2 years, 3 months ago
answer is D
upvoted 1 times
...
Meira088
2 years, 4 months ago
Selected Answer: B
correct answer is B
upvoted 2 times
...
tururu1496
2 years, 7 months ago
Selected Answer: B
Answer: B (https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/vlan-tagged-traffic.html)
upvoted 2 times
...
Qintao
3 years, 6 months ago
Bad question!
upvoted 2 times
...
webmanau
3 years, 7 months ago
It's option B and anyone who says otherwise has probably never configured on of these firewalls. Insertion into a trunk needs vWire. C and D are plain rubbish and A does not allow individual zones. I actually set this up 7 years ago so no need to guess.
upvoted 2 times
...
shetoshandasa
3 years, 7 months ago
Answer is "B", "C" doesn't seem to be correct because 2 layers 3 interfaces in the firewall will force you to change the g/w for all endpoints to be the FW instead of the core switch, moreover "Do not assign any interface an IP address" is another obstacle, then how will you route the traffic from the ingress port to the egress one !!
upvoted 2 times
...
lucaboban
3 years, 7 months ago
Correct answer is C
upvoted 1 times
GivemeMoney
2 years, 9 months ago
Explain why?
upvoted 2 times
...
...
bmarks
3 years, 8 months ago
Best Answer = B Based on PAN Documentation on Virtual Wire Subinterfaces: Virtual wire deployments can use virtual wire subinterfaces to separate traffic into zones. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces.html C is L3 subinterfaces that will require an IP address to pass traffic
upvoted 4 times
...
DocHoliday
3 years, 9 months ago
c can't be correct layer 3 always needs an IP
upvoted 1 times
...
NatiCare
3 years, 9 months ago
The correct is D, C is layer 3.
upvoted 2 times
...
duyvo
3 years, 9 months ago
Ans is D. A. Define a range of "0-4096" will allow all VLAN pass through the vWire but can not separate zones. B. Can not assign VLAN ID to the "Tag Allowed" of V-Wire subinterfaces C. Layer 3 subinterfaces can not link between two physical interface unless use vWire subinterfaces or Layer 2 subinterfaces
upvoted 1 times
...
Sarbi
3 years, 10 months ago
C is correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago