Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PSE-SoftwareFirewall Topic 4 Question 22 Discussion

Actual exam question for Palo Alto Networks's PSE-SoftwareFirewall exam
Question #: 22
Topic #: 4
[All PSE-SoftwareFirewall Questions]

Why are VM-Series firewalls and hardware firewalls that are external to the Kubernetes cluster problematic for protecting containerized workloads?

Show Suggested Answer Hide Answer
Suggested Answer: B

Visibility into application-level cluster traffic:

VM-Series firewalls and hardware firewalls that are external to the Kubernetes cluster lack the necessary visibility into the traffic and communications occurring at the application level within the cluster. This limitation impedes their ability to effectively protect containerized workloads.


Palo Alto Networks Kubernetes Security Guide

Contribute your Thoughts:

Theron
3 days ago
I agree with Ilene, external firewalls have no visibility into application-level cluster traffic.
upvoted 0 times
...
Dulce
3 days ago
B definitely makes the most sense. You can't protect what you can't see, and those external firewalls are basically blind to the inner workings of the cluster.
upvoted 0 times
...
Dalene
4 days ago
I'd go with D. Those firewalls don't scale independently, so they can't keep up with the dynamic nature of Kubernetes. Imagine trying to wrestle a tiger with a leash, that's what it must feel like.
upvoted 0 times
...
Ilene
5 days ago
I think VM-Series firewalls and external hardware firewalls are problematic for protecting containerized workloads because they are located outside the cluster.
upvoted 0 times
...
Val
13 days ago
Option B sounds right to me. External firewalls have no idea what's happening inside the Kubernetes cluster, so they can't really protect those containerized workloads effectively.
upvoted 0 times
Venita
39 minutes ago
A) They function differently based on whether they are located inside or outside of the cluster.
upvoted 0 times
...
...

Save Cancel