Q: 15
A network security engineer needs to implement segmentation but is under strict compliance
requirements to place security enforcement as close as possible to the private applications hosted in
Azure. Which deployment style is valid and meets the requirements in this scenario?
Options
Discussion
Option C, Layer 2 is a trap, VM-Series in Azure only supports Layer 3 interfaces so B doesn’t fit.
Pretty sure C. VM-Series is the only Palo Alto NGFW you can actually deploy in Azure, and for segmentation you'd want Layer 3 so it can inspect routed traffic between subnets. B looks tempting at first but PA-Series isn't supported in Azure, so that's the trap here. Agree or see a different use case?
I don’t think it’s A. C makes more sense since the VM-Series is designed for Azure and Layer 3 zones are required for proper segmentation with routing between subnets. Layer 2 isn’t really supported in Azure like in physical networks, so I think A and B might be traps here. Not totally confident but leaning C.
I don’t think it’s C. B. The PA-Series can do Layer 2 zones for segmentation, so I picked B since it fits the logical segmentation part. Maybe I missed something with Azure support?
B or C from what I've seen in the official study guide and Azure-focused labs. I've noticed most practice exams steer you toward C, but B looks possible if you aren't thinking about the cloud platform restrictions.
C only VM-Series with Layer 3 zones makes sense here in Azure. You can't use Layer 2 or PA-Series. Pretty confident.
Hard to say, C. Only VM-Series is supported in Azure, and it only does Layer 3 interfaces for segmentation there. Layer 2 options are kind of a trap because they're not available in that environment. If compliance wants security enforcement right up to the apps, Layer 3 zones on VM-Series is the correct design. Open if anyone’s seen a new Azure update that would change this.
Noticed B and D mention PA-Series, but that's hardware and not for Azure. Why use those in this scenario?
Don't think A or B work since Layer 2 isn't supported by VM-Series in Azure, that's a common trap. C is the one that fits-VM-Series for Azure with Layer 3 zones gives you segmentation and meets compliance rules. If anyone thinks Layer 2 works natively in cloud, I'd double-check that, pretty sure it's unsupported.
C
A
I figured Layer 2 zones on the VM-Series could handle segmentation in Azure since it lets you isolate traffic without complex routing. Maybe I’m missing something with the compliance part but A looked fine to me.
I figured Layer 2 zones on the VM-Series could handle segmentation in Azure since it lets you isolate traffic without complex routing. Maybe I’m missing something with the compliance part but A looked fine to me.
Be respectful. No spam.