exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 468 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 468
Topic #: 1
[All PCNSE Questions]

A network security administrator wants to configure SSL inbound inspection.

Which three components are necessary for inspecting the HTTPS traffic as it enters the firewall? (Choose three.)

  • A. An SSL/TLS Service profile
  • B. The web server's security certificate with the private key
  • C. A Decryption profile
  • D. A Decryption policy
  • E. The client's security certificate with the private key
Show Suggested Answer Hide Answer
Suggested Answer: BCD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Marshpillowz
9 months ago
Selected Answer: BCD
B, C and D correct
upvoted 1 times
...
Metgatz
10 months, 2 weeks ago
Selected Answer: BCD
B. The web server's security certificate with the private key C. A Decryption profile D. A Decryption policy
upvoted 1 times
...
Andromeda1800
10 months, 3 weeks ago
B and D are mandatory (server's certificate and private key + decryption policy). C decryption profile is not mandatory but is highly recommended. Even when you set up SSL Inbound Inspection policy, certificate setting is highlighted in red framing meaning it's mandatory, while decryption profile setting in the policy does NOT have red framing, meaning that it's not mandatory. So the syntax of this question and provided options for answers are not really 100% correct.
upvoted 1 times
...
Eiffelsturm
11 months ago
Definetly B and D, but a Decryption Profile is not necessary: "Although Decryption profiles are optional, it is best to include a Decryption profile with each Decryption policy rule to prevent weak, vulnerable protocols and algorithms from allowing questionable traffic on your network". The questions asks for necessary components.
upvoted 1 times
...
MHy2k
1 year, 1 month ago
BCD Use SSL Inbound Inspection to decrypt and inspect inbound SSL traffic destined for a network server (you can perform SSL Inbound Inspection for any server if you load the server certificate onto the firewall). With an SSL Inbound Inspection Decryption policy enabled, the firewall decrypts all SSL traffic identified by the policy to clear text traffic and inspects it. The firewall blocks, restricts, or allows the traffic based on the Decryption profile attached to the policy and the Security policy that applies to the traffic, including any configured Antivirus, Vulnerability Protection, Anti-Spyware, URL Filtering, and File Blocking profiles. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-ssl-inbound-inspection
upvoted 1 times
...
Marbot
1 year, 8 months ago
Selected Answer: BCD
Reference: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-ssl-inbound-inspection
upvoted 2 times
...
DenskyDen
1 year, 8 months ago
Selected Answer: BCD
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PNBoCAO
upvoted 3 times
...
droide
1 year, 8 months ago
Selected Answer: BCD
BCD correct answers
upvoted 1 times
...
djedeen
1 year, 10 months ago
Selected Answer: BCD
Configuring SSL Inbound Inspection includes: - Installing the targeted server certificate on the firewall. - Creating an SSL Inbound Inspection Decryption policy rule. - Applying a Decryption profile to the policy rule.
upvoted 2 times
...
Maryamk
1 year, 10 months ago
BCD correct answers
upvoted 2 times
...
juangsap
1 year, 10 months ago
Selected Answer: BCD
as a link from evdw
upvoted 1 times
...
evdw
1 year, 10 months ago
Selected Answer: BCD
Correct answer B,C,D https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-ssl-inbound-inspection
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago