exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 344 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 344
Topic #: 1
[All PCNSE Questions]

An engineer needs to see how many existing SSL decryption sessions are traversing a firewall.
What command should be used?

  • A. debug sessions | match proxy
  • B. debug dataplane pool statistics | match proxy
  • C. show dataplane pool statistics | match proxy
  • D. show sessions all
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
al12345
Highly Voted 2 years, 1 month ago
Selected Answer: B
A - not exist B - correct https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhdCAC C - not exist D - incorect - should be - show session all filter application ssl (but show all session, not a count number of sessions)
upvoted 11 times
...
Metgatz
Most Recent 10 months, 4 weeks ago
B - correct https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhdCAC
upvoted 1 times
...
Sammy3637
10 months, 4 weeks ago
Selected Answer: B
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhdCAC
upvoted 1 times
...
playthegamewithme
1 year, 5 months ago
B https://kb.itzecurity.com/2014/04/how-to-implement-ssl-decryption.html#:~:text=To%20see%20how%20many%20existing%20SSL%20decryption%20sessions,there%20are%205%20SSL%20sessions%20being%20decrypted%20%281024%E2%80%931019%3D5%29%3A
upvoted 1 times
...
aatechler
1 year, 8 months ago
Selected Answer: B
Helpful CLI Commands To see how many existing SSL decryption sessions are going through the device, use this CLI command: > debug dataplane pool statistics | match proxy https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0
upvoted 1 times
...
confusion
2 years ago
Selected Answer: B
B is the most correct and exact answer
upvoted 1 times
...
TAKUM1y
2 years ago
Selected Answer: B
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClhdCAC
upvoted 2 times
...
mysteryzjoker
2 years, 1 month ago
Selected Answer: B
I agree b) show session all can be useful command, but on a production network with thousands of sessions it'd take a while to count how many there were.
upvoted 2 times
...
secdaddy
2 years, 1 month ago
Could be B as per al1234 Could be D as per mizuno92 except the full command required is 'show session all filter ssl-decrypt yes count yes' I'm going to guess B is 'better' between these two
upvoted 2 times
...
mizuno92
2 years, 1 month ago
Selected Answer: D
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClsVCAS
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago