Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium

A company is designing a new network segment for IoT devices. These devices require outbound internet access for firmware updates and telemetry, but they should be strictly prevented from initiating any inbound connections or communicating with internal corporate networks. The firewall will operate in Layer 3 mode. Which security zone design and policy approach best meets these requirements?

  1. APlace IoT devices in the 'Trust' zone and allow all outbound traffic.
  2. BCreate a dedicated 'IoT' zone, allow outbound to 'Untrust' (Internet) for specific applications, and deny all traffic to other internal zones.
  3. CCreate a dedicated 'IoT' zone, allow all outbound traffic to 'Untrust', and allow inbound from 'Trust' for updates.
  4. DPlace IoT devices in the 'Untrust' zone and rely on default deny rules.
Show answer & explanation

Correct answer: B. Create a dedicated 'IoT' zone, allow outbound to 'Untrust' (Internet) for specific applications, and deny all traffic to other internal zones.

Creating a dedicated 'IoT' zone provides logical isolation. Allowing outbound to 'Untrust' for specific applications ensures necessary internet access while adhering to least privilege. Explicitly denying traffic to other internal zones prevents unauthorized communication, meeting all requirements for strict prevention of inbound and internal communication.

Why the other options are wrong

  • A. Placing IoT devices in the 'Trust' zone is a security risk, as 'Trust' zones typically have broad permissions and could expose internal networks to compromised IoT devices.
  • C. Allowing 'inbound from Trust for updates' contradicts the requirement to 'strictly prevent from initiating any inbound connections' from the perspective of the IoT devices themselves. While updates might be necessary, they should be pulled by the IoT devices or managed through a more secure, controlled mechanism, not by allowing general inbound connections.
  • D. Placing IoT devices in the 'Untrust' zone is not standard and would make it difficult to apply granular outbound policies or manage them effectively within a secure context.

Security Zone Segmentation

The practice of dividing a network into distinct security zones (e.g., Trust, Untrust, DMZ, IoT) based on their security posture and communication requirements. Firewalls are then used to control traffic flow between these zones, enforcing a 'least privilege' model.

  • Logical network isolation
  • Enforces granular traffic control
  • Reduces attack surface
  • Based on security posture

Memory trick: Zones: Walls that segment and protect your network.

More Plan and Design questions