Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformMedium

A security analyst is investigating unusual outbound traffic from several internal workstations. To gain immediate visibility into the traffic patterns without disrupting the existing production network, the analyst decides to deploy a Palo Alto Networks firewall. The firewall should receive a mirrored copy of the traffic and analyze it without being in the data path. Which deployment mode is most suitable for this scenario?

  1. ALayer 3
  2. BTap
  3. CHA Active/Passive
  4. DVirtual Wire (Inline)
Show answer & explanation

Correct answer: B. Tap

Tap mode allows the firewall to receive a mirrored copy of network traffic (e.g., from a SPAN port) and analyze it passively. It provides full visibility into traffic patterns without being in the data path, ensuring no disruption to the production network, which is ideal for initial investigations or monitoring.

Why the other options are wrong

  • A. Layer 3 mode is an inline deployment that would require network changes and be in the data path.
  • C. HA Active/Passive is a redundancy configuration, not a deployment mode for passive monitoring.
  • D. Virtual Wire (Inline) mode is also an inline deployment that would be in the data path and could cause disruption if misconfigured.

Tap Mode

A passive deployment mode for Palo Alto Networks firewalls where it receives a mirrored copy of network traffic for analysis, without being in the active data path.

  • Provides visibility without disruption.
  • Cannot block or modify traffic.
  • Used for monitoring, forensics, and proof-of-concept.

Memory trick: Tap Mode is like a silent observer, listening in without interfering.

More Palo Alto Networks Security Platform questions