exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 318 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 318
Topic #: 1
[All PCNSE Questions]

An engineer wants to implement the Palo Alto Networks firewall in VWire mode on the internet gateway and wants to be sure of the functions that are supported on the vwire interface.
What are three supported functions on the VWire interface? (Choose three.)

  • A. IPSec
  • B. OSPF
  • C. SSL Decryption
  • D. QoS
  • E. NAT
Show Suggested Answer Hide Answer
Suggested Answer: CDE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nose999
Highly Voted 2 years, 8 months ago
Selected Answer: CDE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces
upvoted 12 times
...
al12345
Highly Voted 2 years, 7 months ago
Selected Answer: CDE
The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active HA, QoS, zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and NAT. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces
upvoted 7 times
...
ali_sh85
Most Recent 9 months, 3 weeks ago
Selected Answer: CDE
The virtual wire supports the blocking or allowing of traffic based on the virtual LAN (VLAN) tags. The virtual wire also supports Security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active high availability (HA), QoS, zone protection (with some exceptions), non-IP protocol protection, denial of service (DoS) protection, packet buffer protection, tunnel content inspection,and NAT.
upvoted 1 times
...
123XYZT
10 months, 3 weeks ago
CDE A is incorrect because: You wouldn’t use a virtual wire deployment for interfaces that need to support switching, VPN tunnels, or routing because they require a Layer 2 or Layer 3 address.
upvoted 1 times
...
JRKhan
1 year, 3 months ago
Selected Answer: CDE
CDE is correct. Vwire interfaces cannot be used as IPsec termination points.
upvoted 1 times
...
Metgatz
1 year, 4 months ago
CDE are the correcto options
upvoted 1 times
...
Xuzi
1 year, 5 months ago
Selected Answer: CDE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces
upvoted 1 times
...
Nawda
1 year, 7 months ago
Selected Answer: CDE
no switching or routing for Vwire
upvoted 1 times
...
dgonz
1 year, 8 months ago
Selected Answer: CDE
CDE are correct
upvoted 1 times
...
sujss
2 years ago
Selected Answer: CDE
I guess easiest approach for this is discard anything that needs an IP (or MAC) as Vwire interfaces do not support IP or MAC
upvoted 1 times
...
GohanF2
2 years, 2 months ago
It is CDE.
upvoted 1 times
...
DenskyDen
2 years, 3 months ago
CDE. The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, "DECRYPTION", LLDP, active/passive and active/active HA, "QOS", zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and "NAT".
upvoted 1 times
...
aatechler
2 years, 4 months ago
Selected Answer: CDE
You wouldn’t use a virtual wire deployment for interfaces that need to support switching, VPN tunnels, or routing because they require a Layer 2 or Layer 3 address. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces
upvoted 1 times
...
awtsuritacuna
2 years, 4 months ago
Options: B/D/E - The virtual wire allows the firewall to maintain a transparent presence acting as a pass-through link, while still providing security, NAT, and QoS services. - In order for routing (Layer 3) control packets to pass through a virtual wire, you must apply a security policy rule that allows the traffic to pass through. For example, apply a security policy rule that allows an application such as BGP or OSPF. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/layer-2-and-layer-3-packets-over-a-virtual-wire#id176TE0F0UDU_id176TE000DXC
upvoted 1 times
...
confusion
2 years, 6 months ago
Selected Answer: CDE
CDE links from nose999, TAKUM1y and al12345 point that clearly
upvoted 1 times
...
TAKUM1y
2 years, 6 months ago
Selected Answer: CDE
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces "The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active HA, QoS, zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and NAT."
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago