exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 517 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 517
Topic #: 1
[All PCNSE Questions]

An administrator has been tasked with deploying SSL Forward Proxy.

Which two types of certificates are used to decrypt the traffic? (Choose two.)

  • A. Device certificate
  • B. Subordinate CA from the administrator’s own PKI infrastructure
  • C. Self-signed root CA
  • D. External CA certificate
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Angelafp
2 weeks, 5 days ago
Selected Answer: BD
In this case si B and D, it is uses the B the subordinate CA certificate to decrypt the traffic with our internal host, and the D the External CA certificate to decrypt the traffic with the server. Sorry but the B only would be posible if we import the certificate in the web browser.
upvoted 1 times
...
Marshpillowz
8 months ago
Selected Answer: BC
B and C are correct
upvoted 1 times
...
Andromeda1800
9 months, 3 weeks ago
Selected Answer: BC
B and C
upvoted 1 times
...
McMarius11
11 months, 3 weeks ago
Selected Answer: BC
B&C is correct!
upvoted 1 times
...
HaillyHops
1 year, 2 months ago
Why you guys are saying C is correct without knowing if the Self-signed CA is injected in the user's browser ? Because if it's not, the browser will show a warning. As mentioned in: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-forward-proxy#idb39a2a9b-9c02-413b-ab1c-dc687b7bcb21 "This method (Self-signed Certificates) requires that you need to install the self-signed certificates on all of your network devices so that those devices recognize the firewall’s self-signed certificates. " I'd say BD because the certificate forwarded in these both cases will be accepted by the browser as trusted. C is correct if we know that the Self-signed CA was added to the user's browser.
upvoted 1 times
HaillyHops
1 year, 2 months ago
Ignore the above, it's BC because the cert is only used to decrypt as per the question
upvoted 3 times
...
...
Mohamed_Waly
1 year, 2 months ago
Selected Answer: BC
B&C are correct
upvoted 1 times
...
Knowledge33
1 year, 3 months ago
BC are correct. check question 448
upvoted 1 times
...
abanaaba
1 year, 3 months ago
Selected Answer: BC
correct answer is B and C
upvoted 2 times
...
mercysayno765
1 year, 3 months ago
I think it's C and D, based on link below. But I'm not sure. B also looks like an option. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-forward-proxy#idb39a2a9b-9c02-413b-ab1c-dc687b7bcb21
upvoted 1 times
Knowledge33
1 year, 3 months ago
we don't need external. D is false.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago