Portfolio Overview
Data Lake, XDR, AutoFocus, XSOAR
Network endpoints and cloud
Three Pillars are Enterprise, Cloud and the Future
Strata, Prisma and Cortex
Key elements
- Complete Visibility
- Reduce attack surface
- Prevent know threats
- Prevent unknown threats (ML)
Secure the Enterprise
Portfolio of products Strata, VM and CN series, Subscription service, Panorama, Wildfire, GlobalProtect (VPN), Prisma (SaaS, cloud, Access)
Prisma Saas, Cloud and Access
Secure the Future
AI based Cortex subscription services
Data Lake (logs) XDR (prevents malware, blocks exploits, and analyses suspicious patterns through behavioural threat protection), AutoFocus, XSOAR
- XSOAR and Xpanse can overcome skills shortages
Next Gen FW Architecture
Single pass (operations per packet) architecture is the strength Sp3
2 panes Control pane (management, config reporting) and data plane sig matching security and network processing
Content, App and user ID reading
Architecture 2 planes
Control (management MGT interface/console and Data (could be three Signature matching, security processing, networking processing)
Zero Trust Architecture
Always verify
Inspect perimeter north--><--south
Inspect internal traffic east--><--west
Firewall Offering
Strata 3 forms are Hardware, PA software (VM and CN) and (cloud Prisma)
PA series NGF from PA 7000, 5000, 3200 800 (branch offices) 400, 200, 20
3x00 5x00 7x00 series
K2 5G ready and IOT
Virtual System
Separate logical FW in a single physical FW (used in multiple customers or departments) depends on license 3000 and above
VM series model
on Amazon, cloud vendors
VM-700 VM-500 VM-100 VM-50
Dedicated memory (minimum) 4.5GB Dedicated disk drive capacity (minimum) 32GB disk space
V100 double VM 300 VM 500 VM 700
2 4 8 16 Firewall throughput (App
1 2 4 8 Threat prevention throughput
1500 3000 6000 1200 New sessions per second
CN Series FW same as PA and VM series
Container (integrates into Kubernetes clusters,)
K2 for 5G networks (secure and express modes) mobile/IOT network protection
Prisma Access SASE secure access service edge convergence of WAN security
1. A strength of the Palo Alto Networks firewall is:
hardware consolidation - data and control plane processing is improved and performed in successive linear fasion
its single-pass parallel processing (SP3) engine and software performs operations once per packet
increased buffering capability.
2. True. The CN-Series firewalls deliver the same capabilities as the PA-Series and VM-Series firewalls.
3. True. Traffic protection from external locations where the egress point is the perimeter is commonly referred to as “North-South” traffic.
4. The first important task of building a Zero Trust Architecture is to identify __________________.
traffic
the protect surface
microperimeter
interdependencies
5. What is the method used to create a Zero Trust policy that answers the 'who, what, when, where, why and how' definition?
Logging
Full Authentication
Kipling
Never Trust - Always Verify
6. Which object cannot be segmented using virtual systems on a firewall?
MGT interface
Data Plane Interface
Administrative Access
Network Security Zone
7. Which Palo Alto Networks Cortex technology prevents malware, blocks exploits, and analyses suspicious patterns through behavioural threat protection?
XDR
XSOAR
Data Lake
AutoFocus
8. Which Palo Alto Networks Next Generation VM Series Model requires a minimum of 16 GB of memory and 60 GB of dedicated disk drive capacity?
VM-50
VM-700
VM-100
VM-500
9. Which Palo Alto Networks Prisma technology provides continuous security monitoring, compliance validation, and cloud storage security capabilities across multi-cloud environments. In addition, you can simplify security operations through effective threat protections enhanced with comprehensive cloud con?
Cloud
Compliance
SaaS
Access
10.Which Palo Alto Networks product for securing the enterprise extends the enterprise perimeter to remote offices and mobile users?
a. WildFire
b. VM-Series
c. Panorama
d. GlobalProtect
11.Which series of firewall is a high-performance physical appliance solution?
CN
HA
VM
PA
12.Which series of Palo Alto Networks Next Generation Firewall offers two modes, Secure Mode, and Express Mode?
K2
CN
VM
VS
13. Which Strata product provides centralized firewall management and logging?
GlobalProtect
Panorama
WildFire
Prisma Access
- Log in to post comments
Comments