Question 1
A security architect is designing a Zero Trust architecture for a financial institution. The organization requires that all internal east-west traffic between the 'HR-VLAN' and 'Finance-VLAN' be inspected for threats, specifically looking for lateral movement and exploit attempts. Currently, these VLANs are routed via a core switch with ACLs. Which deployment mode should the architect implement on a Palo Alto Networks NGFW to achieve deep packet inspection without re-architecting the entire Layer 3 routing topology?
Answer and explanation
Correct answer: B
Virtual Wire (VWire) mode allows the firewall to be inserted transparently into an existing network segment. It bridges two interfaces without requiring IP address changes or routing table modifications on adjacent devices, making it ideal for inspecting east-west traffic without disrupting the existing L3 topology.