exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 340 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 340
Topic #: 1
[All PCNSE Questions]

A company requires that a specific set of ciphers be used when remotely managing their Palo Alto Networks appliances.
Which profile should be configured in order to achieve this?

  • A. Certificate profile
  • B. SSL/TLS Service profile
  • C. SSH Service profile
  • D. Decryption profile
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nose999
Highly Voted 2 years, 1 month ago
Selected Answer: C
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certificate-management/configure-an-ssh-service-profile
upvoted 8 times
...
ConfuzedOne
Highly Voted 1 year, 5 months ago
Selected Answer: C
SSL/TLS profile is only the TLS versions, not ciphers. Decryption Profile is for SSL Inbound and Forward Proxy applications, not mgmt of the PANW Firewall. There's also KB articles to strengthen SSH, but I couldn't find any for HTTPS, on the mgmt interface: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004OOQCA2&lang=en_US%E2%80%A9 So it seems C is the winner.
upvoted 7 times
...
legrandchuck
Most Recent 3 weeks, 3 days ago
Selected Answer: C
C is correct, for the SSL/TLS serivce profile you may choose the max and min TLS version burt not specify which cyphers, this option is only available for SSH service profile.
upvoted 1 times
...
franko_72
10 months, 3 weeks ago
Go to Device >> Certificate Management >> SSH Service Profile >> Add the ciphers, message authentication codes, or key exchange algorithms the profile will support. So it's C
upvoted 2 times
...
RoamingFo
11 months, 1 week ago
Selected Answer: B
For GUI (typical option)...SSL/TLS Service Profile, ciphers can be set on CLI... B is Correct For CLI... SSH Service Profile...C is Correct Confusing Question
upvoted 7 times
...
[Removed]
1 year, 6 months ago
Im taking B, you can restrict ciphers form CLI...
upvoted 1 times
...
TheIronSheik
1 year, 8 months ago
Selected Answer: C
Looking at both options on a FW, only the SSH Service Profile has an option for ciphers.
upvoted 3 times
...
DenskyDen
1 year, 8 months ago
B. you can use a profile to restrict the cipher suites that are available for securing communication with the clients requesting the services. This improves network security by enabling the firewall or Panorama to avoid SSL/TLS versions that have known weaknesses.
upvoted 1 times
DenskyDen
1 year, 8 months ago
They are correct. it should be C.
upvoted 1 times
...
...
djedeen
1 year, 9 months ago
Selected Answer: B
I think it is B, don't know anyone that is going to manage the FWs via SSH (which is option C).
upvoted 1 times
djedeen
1 year, 9 months ago
Changing this to C after further review. You cannot specify ciphers on a SSL/TLS profile, only versions of TLS, so to meet the question requirements it will need to be managed via SSH.
upvoted 1 times
...
...
Kaspinas
1 year, 10 months ago
Selected Answer: C
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/certificate-management/configure-an-ssh-service-profile Step1 4. (Optional) Add the ciphers, message authentication codes, or key exchange algorithms the profile will support.
upvoted 1 times
PaloSteve
1 year, 3 months ago
"use SSL/TLS service profiles...defining the protocol versions, you can use a profile to RESTRICT THE CIPHER SUITES that are available for securing communication with the clients requesting the services. This improves network security by enabling the firewall or Panorama to avoid SSL/TLS versions that have known weaknesses."
upvoted 1 times
...
...
TAKUM1y
2 years ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/certificate-management/configure-an-ssltls-service-profile
upvoted 1 times
...
secdaddy
2 years ago
Further on this, in Best Practices for Securing Administrative Access there are mentions of both ssh and https but this text seems possibly relevant to this question (in support of C) : "...in the SSL/TLS profile, set the Min version to TLSv1.2 so you use the strongest protocol and set the Max version to Max so that you continue to use the strongest protocol as stronger versions become available." https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/getting-started/best-practices-for-securing-administrative-access#id1817C0G205Q
upvoted 1 times
secdaddy
2 years ago
Correction : I meant in support of B not C. There is no similar recommendation in the best practices doc for ssh ciphers. I'll stick with B on this.
upvoted 2 times
...
...
mysteryzjoker
2 years, 1 month ago
I agree C - for TLS/SSL you need to configure certs etc. rather than encryption protocols.
upvoted 1 times
secdaddy
2 years ago
Certs provide authentication and then use encryption protocols to provide confidentiality and integrity - using ciphers. https://www.ibm.com/docs/en/ibm-mq/9.1?topic=tls-how-provides-identification-authentication-confidentiality-integrity
upvoted 1 times
...
secdaddy
2 years ago
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmqeCAC
upvoted 2 times
...
...
secdaddy
2 years, 1 month ago
Could be either b or c as both are for remotely managing. Maybe B is better as day to day will usually be via https ? https (B) : Palo Alto Networks firewalls and Panorama use SSL/TLS service profiles to specify a certificate and the allowed protocol versions for SSL/TLS services. The firewall and Panorama use SSL/TLS for Captive Portal, GlobalProtect portals and gateways, inbound traffic on the management (MGT) interface, the URL Admin Override feature, and the User-ID™ syslog listening service. By defining the protocol versions, you can use a profile to restrict the cipher suites that are available for securing communication with the clients requesting the services. ssh (C) By default, SSH supports all ciphers, key exchange algorithms, and message authentication codes, which leaves your connection vulnerable to attack. With an SSH service profile, you can restrict the algorithms your SSH server supports. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/certificate-management/configure-an-ssh-service-profile
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago