QuestionQ16

Planning and Design

Which statement accurately describes how the Prisma SD-WAN zone-based firewall operates within a branch network?

  • A North-south traffic (internet/WAN egress) is handled by zone-based firewall and relies on external firewalls for east-west segmentation.
  • B East-west traffic between the zones can be explicitly blocked, but traditional Access Control List (ACLs) are required to block north-south traffic.
  • C North-south traffic is handled by application-aware policies, while east-west traffic requires traditional Access Control List (ACLs).
  • D Security zones enable granular control over both WAN-to-LAN and LAN-to-WAN as well as east-west (LAN-to-LAN) traffic flows within the branch.
Explanation

Prisma SD-WAN security zones are enforcement boundaries that can be associated with LAN, WAN, and VPN networks. Zone-based security rules use source and destination zones to allow, deny, or reject application traffic, enabling control of WAN-to-LAN, LAN-to-WAN, and east-west LAN-to-LAN flows within a branch. Prisma SD-WAN ZBFW

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!