exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 278 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 278
Topic #: 1
[All PCNSE Questions]

An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)

  • A. GlobalProtect HIP
  • B. source users
  • C. App-ID
  • D. URL categories
  • E. source and destination IP addresses
Show Suggested Answer Hide Answer
Suggested Answer: BDE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nose999
Highly Voted 2 years, 8 months ago
Selected Answer: BDE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule
upvoted 7 times
bimyo
2 years, 7 months ago
BDE is correct, checked it in LAB
upvoted 3 times
...
...
ali_sh85
Most Recent 9 months, 3 weeks ago
Selected Answer: BDE
Decryption and Authentication policies dont use application
upvoted 1 times
...
327c7c8
1 year, 1 month ago
Selected Answer: BDE
You cannot decrypt any traffic from any type of VPN, if it is GlobalProtect or AnyConnect etc. App-ID is a function in the NGFW not an element in which you can use in a oolicy. But source user, Source IP and Destination IP you can use in the SSL decrypt policy. there are HIP option you can use but this is not associated with the GlobalProtect.
upvoted 1 times
...
findkeywordcommand
1 year, 1 month ago
Who decides about what is right here? You can easily check that App-ID or GlobalProtect HIP aren't in the Decryption Policy Rule options. Disappointed with this site
upvoted 1 times
...
Erle1988
1 year, 11 months ago
Selected Answer: BDE
BDE is correct
upvoted 1 times
...
[Removed]
2 years ago
BDE Buuuuut!!! im checking my firewall and you can put HIP at source tab.... so global protect hip should be ok i think :O
upvoted 1 times
...
certprep2021
2 years, 1 month ago
Selected Answer: BDE
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0 "In particular, decryption can be based upon URL categories, source users, and source/destination IP addresses."
upvoted 3 times
...
djedeen
2 years, 3 months ago
Selected Answer: BDE
BDE: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule
upvoted 1 times
...
DenskyDen
2 years, 3 months ago
BDE. 1.Users—Select Source and set the Source User for whom to decrypt traffic. 2. IP addresses, address objects, and/or address groups—Select Source and/or Destination to match to traffic based on Source Address and/or the Destination Address 3. Select Service/URL Category to set the rule to match to traffic based on service
upvoted 1 times
...
confusion
2 years, 6 months ago
Selected Answer: BDE
BDE Src: Zone, Address, User Dst: Zone, Address Service/URL category
upvoted 1 times
...
TAKUM1y
2 years, 6 months ago
Selected Answer: BDE
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule
upvoted 2 times
...
Alen
2 years, 7 months ago
Selected Answer: BDE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago