
Palo Alto NetworksCertified Network Security Architect
Domain 9Objective 5
9.5 Design to GCP NGFW Standards NETWORK-SECURITY-ARCHITECT Practice Questions (Page 2)
Part of the Public Cloud domain, which accounts for 11% of the NETWORK-SECURITY-ARCHITECT exam.
19questions here
4free pages
4concepts
11%of the exam
Questions 6–10
- 6
In an active/passive HA deployment of NGFW in GCP, what is the primary role of the passive firewall?
Select an answer first - 7
A company is designing an NGFW deployment in GCP. They have two VPCs that need to communicate, and they want to inspect the traffic. They are considering two options: (1) deploy an NGFW in each VPC, or (2) use a centralized NGFW in a hub VPC. They are concerned about the cost of the deployment. What is the primary trade-off?
Select an answer first - 8
When integrating an internal load balancer with an NGFW for traffic steering, what is a key design consideration?
Select an answer first - 9
Which GCP NGFW insertion mode is best suited for a design that requires centralized inspection of traffic from multiple VPCs, where each VPC connects to a central hub VPC that hosts the NGFW?
Select an answer first - 10
A company is deploying an NGFW in GCP for a mission-critical application. They need to ensure that if the active NGFW fails, the passive NGFW takes over with minimal disruption. What should they configure to achieve this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.