Palo Alto Networks Certified Network Security Engineer (PCNSE) — Question 503

A company wants to install a NGFW firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and to assign untagged (native) traffic to its own zone.
Which option differentiates multiple VLANs into separate zones?

Answer options

Correct answer: B

Explanation

Option B is correct because it allows for each VLAN to be assigned to its own zone by using V-Wire subinterfaces, enabling separate management for both tagged and untagged traffic. Options A and D do not provide the same level of specificity for VLAN separation into zones, while option C uses Layer 3 interfaces that do not directly achieve the separation of VLANs into individual zones.