Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformMedium

A security analyst is investigating an incident where unauthorized traffic was detected on a network segment. The Palo Alto Networks firewall in 'Tap' mode captured the traffic. Which statement accurately describes the capabilities of a firewall deployed in Tap mode?

  1. AIt transparently bridges two network segments while enforcing policies.
  2. BIt provides passive monitoring and logging of network traffic without affecting flow.
  3. CIt can actively block malicious traffic based on security policies.
  4. DIt acts as a Layer 3 router, forwarding traffic between different subnets.
Show answer & explanation

Correct answer: B. It provides passive monitoring and logging of network traffic without affecting flow.

Tap mode is a passive deployment where the firewall monitors a copy of network traffic. It provides full visibility and logging capabilities but does not actively participate in the data path, meaning it cannot block or modify traffic. It's often used for out-of-band monitoring or proof-of-concept deployments.

Why the other options are wrong

  • A. Virtual Wire mode transparently bridges and enforces; Tap mode only monitors.
  • C. Blocking traffic is an active function; Tap mode is passive.
  • D. Layer 3 mode acts as a router; Tap mode does not.

Tap Deployment Mode

A passive firewall deployment mode where the Palo Alto Networks firewall receives a copy of network traffic (e.g., via a SPAN port) for monitoring, logging, and analysis, without actively participating in the data path or enforcing policies.

  • Passive monitoring only
  • No policy enforcement (blocking/modifying traffic)
  • Requires a SPAN/mirror port from a switch

Memory trick: Tap mode watches with care, but won't interfere there.

More Palo Alto Networks Security Platform questions