Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformEasy
A network administrator is deploying a new Palo Alto Networks firewall to protect a segment of the internal network. The administrator needs to ensure that all traffic passing through the firewall is inspected and that the firewall can enforce security policies based on applications and users. Which deployment mode is most suitable for this scenario?
- ALayer 3
- BVirtual Wire
- CTap
- DHigh Availability
Show answer & explanationAnswer & explanation
Correct answer: A. Layer 3
Layer 3 deployment mode allows the firewall to act as a router, performing full packet inspection and enforcing security policies based on applications, users, and content. This mode provides the most comprehensive security features.
Why the other options are wrong
- B. Virtual Wire mode offers transparent inspection but does not perform routing.
- C. Tap mode is for passive monitoring only and does not enforce policies.
- D. High Availability is a configuration for redundancy, not a deployment mode itself.
Layer 3 Deployment Mode
A firewall deployment mode where the Palo Alto Networks firewall acts as a router, participating in routing protocols and performing full packet inspection with policy enforcement.
- Acts as a router
- Enforces security policies (App-ID, User-ID, Content-ID)
- Requires IP address configuration on interfaces
Memory trick: Route, Inspect, Protect: Layer 3 is the best.