Exam PCNSE All QuestionsBrowse all questions from this exam
Question 586

A firewall engineer is managing a Palo Alto Networks NGFW which is not in line of any DHCP traffic.

Which interface mode can the engineer use to generate Enhanced Application logs (EALs) for classifying IoT devices while receiving broadcast DHCP traffic?

    Correct Answer: D

    The Tap interface mode is designed to monitor networks passively without being in the direct path of the traffic. Since the firewall is not in the path of any DHCP traffic, the Tap interface can receive and analyze broadcast DHCP traffic to generate Enhanced Application Logs (EALs) for classifying IoT devices. This allows the firewall to gain visibility into the network traffic without needing to route the traffic directly through it.

Discussion
0d2fdfaOption: D

Tap interface does not have to be inline.

MtroOption: D

Tap Interfaces Considerations – If you use a Tap interface to gain visibility into DHCP traffic that the firewall doesn’t ordinarily see, consider the following: Place the tap “north” of any routed boundary where DHCP is configured. This will ensure that the captured traffic is unicast rather than broadcast. (If the firewall with the Tap interface is in the same broadcast domain as the switch that’s mirroring traffic to it, enable DHCP Broadcast Session at DeviceSetupSession.) Use Cases for Tap interfaces Evaluations Networks where DHCP is configured on a device “south” of the firewall Monitor networks that don’t naturally traverse the firewall

ThunnuOption: A

Vwire interface https://docs.paloaltonetworks.com/iot/iot-security-admin/get-started-with-iot-security/firewall-deployment-for-dhcp-visibility/firewall-deployment-options-for-iot-security

apiloranOption: D

Use Cases for Tap interfaces Evaluations Networks where DHCP is configured on a device “south” of the firewall Monitor networks that don’t naturally traverse the firewall Virtual Wire Interfaces Considerations – You might have to use a Virtual Wire (vWire) interface on the firewall to gain visibility into DHCP traffic that the firewall wouldn’t normally see. Consider the following when using a tap interface in this manner: Ensure the Virtual Wire has multicast firewalling enabled. Ensure the Virtual Wire is in the path for DHCP traffic. This traffic can be either broadcast or unicast. Ensure that a security policy rule allowing DHCP exists and that a proper log-forwarding profile is applied to the rule. Ensure the firewall has the available capacity to process the additional traffic. For guidance on mitigating performance impact, see Use a Virtual Wire Interface for DHCP Visibility.

8f3e6caOption: D

Answer is "D" "Ensure the Virtual Wire is in the path for DHCP traffic. This traffic can be either broadcast or unicast." Question states that the firewall is not in the path for DHCP, this eliminates "A".

unless_mailOption: A

the engineer can use the Virtual Wire (vWire) interface mode to generate Enhanced Application Logs (EALs) for classifying IoT devices while receiving broadcast DHCP traffic. Here's why: Virtual Wire Interfaces: The text specifies that for Virtual Wire interfaces, multicast firewalling should be enabled. When the DHCP server and the firewall interface are on the same network segment, the firewall sees only broadcast DHCP traffic. Placing the DHCP server behind a Virtual Wire interface enables the firewall to create EALs for this broadcast traffic. This ensures that the firewall can generate the necessary logs even for broadcast DHCP traffic, which is crucial for IoT device classification.

unless_mailOption: A

A. for sure

hcirOption: A

answer is A. DHCP server, DHCP client and FW on the same broadcast domain means that a VWire interface will only catch the broadcast packets (not the unicast) and will still generate EALs. For a Tap interface to catch the 4 DHCP packets, the switch needs to mirror the traffic.

nchunter

Has anybody recently taken the PCNSE exam? Are there any questions on the exam that are under #300 on the study guide?

nchunter

Has anybody recently taken the PCNSE exam? Are there any questions that are under #300 on the study guide?

LoloshikovichevOption: D

As question states, the firewall is not in the traffic path. Tap is the interface that can receive traffic to identification.

tonykoloOption: D

The question stated "not in line of any DHCP traffic". For Vwire interfaces "Ensure the Virtual Wire is in the path for DHCP traffic. This traffic can be either broadcast or unicast." Tap interface use case "Monitor networks that don’t naturally traverse the firewall". D has to be the right answer.

MostafaNawarOption: A

A, sure

findkeywordcommandOption: A

"Virtual Wire: When the firewall has Virtual Wire interfaces with multicast firewalling enabled, it generates Enhanced Application logs (EALs) for broadcast DHCP sessions." https://docs.paloaltonetworks.com/iot/iot-security-admin/get-started-with-iot-security/firewall-deployment-for-dhcp-visibility/firewall-deployment-options-for-iot-security

jaypogi16Option: A

A. Virtual Wire: When the firewall has Virtual Wire interfaces with multicast firewalling enabled, it generates Enhanced Application logs (EALs) for broadcast DHCP sessions.