Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Architect

Domain 10Objective 5

10.5 Explain Layer 3 Deployment Routing Considerations NETWORK-SECURITY-ARCHITECT Practice Questions (Page 5)

Part of the Private Cloud (PA-Series, VM-Series, Hypervisors) domain, which accounts for 10% of the NETWORK-SECURITY-ARCHITECT exam.

27questions here
6free pages
8concepts
10%of the exam

Questions 21–25

  1. 21application · medium

    A company runs a VM-Series firewall in an active/passive HA pair. The upstream router uses OSPF, and the downstream core switch uses static routes pointing to the firewall's interface IPs. The network team wants the firewall to advertise a default route into OSPF so the upstream router can reach the downstream subnets. The downstream core switch must continue using static routes. Which configuration on the VM-Series firewall satisfies this requirement?

    Select an answer first
  2. 22foundation · easy

    What is the purpose of redistributing routes into BGP?

    Select an answer first
  3. 23expert · hard

    A large enterprise has a PA-Series firewall that redistributes routes between OSPF and BGP. The firewall is connected to an internal OSPF network and an external BGP peer. The network team has configured mutual redistribution: OSPF into BGP and BGP into OSPF. After the configuration, they notice that some OSPF routes are being advertised into BGP, then learned back via BGP, and re-advertised into OSPF, causing suboptimal routing and potential loops. They also observe that the OSPF routing table is growing with external routes that should not be there. What is the most comprehensive solution to prevent this issue?

    Select an answer first
  4. 24foundation · easy

    What is a common risk when redistributing routes between OSPF and another protocol?

    Select an answer first
  5. 25application · medium

    A small branch office has a single PA-Series firewall connecting to the corporate headquarters via a site-to-site VPN. The branch has only one subnet (192.168.10.0/24) and no dynamic routing protocol is running. The network administrator wants to ensure that all traffic from the branch to the corporate network (10.0.0.0/8) is sent through the VPN tunnel, and all other traffic is sent to the local ISP. What is the most appropriate routing configuration on the branch firewall?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.