Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsHard

A global manufacturing company operates several geographically dispersed factories, each with its own local area network (LAN) and internet connection. The central IT team needs to ensure consistent security policies are applied across all locations while allowing local administrators some autonomy for site-specific configurations. They also need to provide secure, encrypted communication channels between all sites and the central data center. Which network security solution is best suited to meet these requirements?

  1. AImplementing individual firewalls at each site with static routing.
  2. BDeploying a distributed firewall architecture with centralized management and VPN capabilities.
  3. CEnforcing host-based firewalls on all end-user workstations.
  4. DUtilizing cloud-based web proxies at each factory.
Show answer & explanation

Correct answer: B. Deploying a distributed firewall architecture with centralized management and VPN capabilities.

A distributed firewall architecture with centralized management allows consistent policy enforcement across all sites from a single console, while VPN capabilities provide secure, encrypted tunnels between sites and the data center. Local administrators can still manage site-specific rules within the central policy framework.

Why the other options are wrong

  • A. Individual firewalls with static routing would be difficult to manage consistently and scale, lacking centralized policy enforcement.
  • C. Host-based firewalls protect individual endpoints but don't secure the network perimeter, enforce global policies, or provide site-to-site connectivity.
  • D. Cloud-based web proxies primarily manage web traffic and don't provide comprehensive network firewalling or site-to-site VPNs.

Distributed Firewall Architecture

A network security approach where firewall functions are deployed across multiple points in a network (e.g., branch offices, data centers), managed from a central console for consistent policy enforcement and visibility.

  • Enables consistent security across dispersed locations.
  • Centralized policy management, distributed enforcement.
  • Often integrated with VPN for secure site-to-site communication.

Memory trick: Many doors, one master key, and secret tunnels for communication.

More Cybersecurity Fundamentals questions