Free PCNSE Exam Braindumps (page: 49)

Page 48 of 152

What are three types of Decryption Policy rules? (Choose three.)

  1. SSL Inbound Inspection
  2. SSH Proxy
  3. SSL Forward Proxy
  4. Decryption Broker
  5. Decryption Mirror

Answer(s): A,B,C


Reference:

https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/decryption/decryption-overview.html#:~:text=The%20firewall%20provides%20three%20types,to%20control%20tunneled%20SSH%20traffic



During SSL decryption, which three factors affect resource consumption? (Choose three.)

  1. key exchange algorithm
  2. transaction size
  3. TLS protocol version
  4. applications ta non-standard ports
  5. certificate issuer

Answer(s): A,B,C


Reference:

https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/decryption/prepare-to-deploy-decryption/size-the-decryption-firewall-deployment



An engineer must configure a new SSL decryption deployment.
Which profile or certificate is required before any traffic that matches an SSL decryption rule is decrypted?

  1. A Decryption profile must be attached to the Decryption policy that the traffic matches.
  2. There must be a certificate with both the Forward Trust option and Forward Untrust option selected.
  3. A Decryption profile must be attached to the Security policy that the traffic matches.
  4. There must be a certificate with only the Forward Trust option selected.

Answer(s): D


Reference:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-forward-proxy



Which two features require another license on the NGFW? (Choose two.)

  1. SSL Inbound Inspection
  2. SSL Forward Proxy
  3. Decryption Mirror
  4. Decryption Broker

Answer(s): C,D


Reference:

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-decryption-port-mirroring.html
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-licenses.html






Post your Comments and Discuss Palo Alto Networks PCNSE exam with other Community members:

PCNSE Exam Discussions & Posts