exam questions

Exam PCNSC All Questions

View all questions & answers for the PCNSC exam

Exam PCNSC topic 1 question 37 discussion

Actual exam question from Palo Alto Networks's PCNSC
Question #: 37
Topic #: 1
[All PCNSC Questions]

SSL Forward Proxy decryption is enabled on the firewall. When clients use Chrome to browse to HTTPS sites, the firewall returns the Forward Trust certificate, even when accessing websites with invalid certificates. The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates.
Which two options will satisfy this requirement? (Choose two.)

  • A. Create a PKI signed Forward Untrust enabled certificate.
  • B. Create a self-signed Forward Untrust enabled certificate.
  • C. Create a Decryption Profile with the “Block sessions with expired certificates” option enabled.
  • D. Remove the Forward Untrust option from the Forward Trust certificate.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
samir111
2 weeks, 3 days ago
Selected Answer: BC
B. Create a self-signed Forward Untrust enabled certificate. C. Create a Decryption Profile with the “Block sessions with expired certificates” option enabled.
upvoted 1 times
Djonzi
2 weeks, 3 days ago
Wrong because of this requirement: "The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates."
upvoted 1 times
...
...
Djonzi
3 weeks, 1 day ago
Selected Answer: BD
Must be self signed and Forwards Trust cert shouldn't be se as Untrust as ewll
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago