exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 274 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 274
Topic #: 1
[All PCNSE Questions]

When planning to configure SSL Forward Proxy on a PA-5260, a user asks how SSL decryption can be implemented using a phased approach in alignment with
Palo Alto Networks best practices. What should you recommend?

  • A. Enable SSL decryption for known malicious source IP addresses
  • B. Enable SSL decryption for malicious source users
  • C. Enable SSL decryption for source users and known malicious URL categories
  • D. Enable SSL decryption for known malicious destination IP addresses
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
secdaddy
Highly Voted 2 years, 1 month ago
Agree C "Phase in decryption. Plan to decrypt the riskiest traffic first (URL Categories most likely to harbor malicious traffic, such as gaming or high-risk) and then decrypt more as you gain experience." https://docs.paloaltonetworks.com/best-practices/9-1/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0
upvoted 5 times
...
Sammy3637
Most Recent 11 months ago
Selected Answer: C
The options are a bit confusing but daddy of security explains it well in the comments
upvoted 1 times
...
lol12
1 year, 10 months ago
Selected Answer: C
C Basically choose control group of users and decrypt to known malicious URl's
upvoted 1 times
...
confusion
2 years ago
Selected Answer: C
C phased starting with specific URL categories
upvoted 1 times
...
TAKUM1y
2 years ago
Selected Answer: C
https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment
upvoted 2 times
...
bimyo
2 years, 1 month ago
C - seems to be correct as the phased approach talks about URL categories. (Financial services & Health-and-medicine) are often times not allowed by law to decrypt. Also it talks about minimizing the impact for end-users. So enabling rule for some user groups and only for specific and malicious URL categories seems to be by far the most correct choice here.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago