Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureEasy

A network security engineer needs to configure a Palo Alto Networks firewall to prevent unauthorized access to the management interface from the internet. Which security zone type should be assigned to the interface connected to the internet to achieve this, while allowing legitimate traffic through other zones?

  1. ATap Zone
  2. BExternal Zone
  3. CHA Zone
  4. DL2 Zone
Show answer & explanation

Correct answer: B. External Zone

Assigning the internet-facing interface to an 'External' zone (or similar custom name representing the untrusted network) allows the creation of security policies to explicitly deny management access from this zone while permitting it from trusted internal zones. This provides granular control and adheres to the principle of least privilege.

Why the other options are wrong

  • A. A Tap Zone is used for passive monitoring of traffic and does not participate in active forwarding or security policies.
  • C. An HA Zone is specifically for High Availability synchronization traffic and not for general internet connectivity.
  • D. An L2 Zone is used for Layer 2 interfaces and doesn't inherently define trust levels for management access control.

Security Zones

Security Zones are logical containers for interfaces that define trust levels and are fundamental for applying security policies.

  • Interfaces must belong to a zone to process traffic.
  • Policies are applied between zones, not interfaces.
  • Common zones include Trust (internal), Untrust (external), DMZ (demilitarized zone).

Memory trick: Zones Guard Access with Logical Boundaries.

More Deploy and Configure questions