Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Paloalto Networks Palo Alto Networks Next-Generation Firewall Engineer NGFW-Engineer Question # 11 Topic 2 Discussion

Paloalto Networks Palo Alto Networks Next-Generation Firewall Engineer NGFW-Engineer Question # 11 Topic 2 Discussion

NGFW-Engineer Exam Topic 2 Question 11 Discussion:
Question #: 11
Topic #: 2

A network architect is planning the deployment of a new IPSec VPN tunnel to connect a local data center to a cloud environment. The plan must include all necessary Security policy configurations for both tunnel negotiation and data transit. Which two Security policy requirements must be included in the implementation plan? (Choose two answers)


A.

The default interzone-default security policy is sufficient to allow the tunnel negotiation traffic between the firewall and the remote peer.


B.

A pair of policies is required to control the flow of data traffic into and out of the security zone assigned to the tunnel interface.


C.

A policy must explicitly permit only the IKE application between the external-facing zone and local zone.


D.

A policy must explicitly permit the IPSec container application between the external-facing zone and local zone.


Get Premium NGFW-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.