exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 191 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 191
Topic #: 1
[All PCNSE Questions]

An engineer must configure a new SSL decryption deployment.
Which profile or certificate is required before any traffic that matches an SSL decryption rule is decrypted?

  • A. A Decryption profile must be attached to the Decryption policy that the traffic matches.
  • B. There must be a certificate with both the Forward Trust option and Forward Untrust option selected.
  • C. A Decryption profile must be attached to the Security policy that the traffic matches.
  • D. There must be a certificate with only the Forward Trust option selected.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vansardo
Highly Voted 2 years, 11 months ago
I think it is A. For example, in SSL Inbound Inspection you do SSL decryption and don't need Forward Trust or Untrust Certificate. You only need a decrypt policy with a decrypt profile.
upvoted 19 times
DavidBackham2020
2 years, 11 months ago
D is not false, but you still need a decryption profile for SSL Forward Proxy. A forward trust certificate alone is insufficient. I agree with vansardo. The absolute minimum is the SSL Inbound Inspection profile (once the certificate an key are known to the firewall). Thus, A seems to be the most correct answer. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/configure-ssl-inbound-inspection.html
upvoted 3 times
...
Mp84047
2 years, 9 months ago
A is the correct answer https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/configure-ssl-inbound-inspection.html
upvoted 3 times
...
secdaddy
2 years, 4 months ago
"(Optional) Select a Decryption Profile to perform additional checks on traffic that matches the policy rule." https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule
upvoted 2 times
...
...
Micutzu
Highly Voted 3 years ago
I believe that in this case the correct answer is D. I tested in my lab and Isn't a must to have a Forward Untrust Certificate. It's a must to have the Forward Trust Certificate defined. Once you create a Decryption Policy Rule, you cannot commit without having a Forward Trust Certificate defined.
upvoted 9 times
...
TeachTrooper
Most Recent 1 week, 1 day ago
Selected Answer: D
it says any traffic "without mentioning ssl forward proxy or inbound inspection" so if one of the answers are correct either for forward proxy or inbound inspection then that's the right answer. in any case decryption profile is not necessary because there is already default-profile.
upvoted 1 times
...
BTSeeYa
5 months ago
Selected Answer: D
Yeah, this is just another terribly worded, "best answer" type question that makes people facepalm at cert tests. If they just stated Forward Proxy in the question, then it would have to be D, but there is no Forward Trust cert used with inbound decryption. Since decryption profiles are optional in either case, I'm going to have to assume they meant Forward Proxy and select D for my answer.
upvoted 1 times
...
Eluis007
8 months, 1 week ago
I believe Option A is the most suitable answer. Here's why: The question explicitly mentions "any traffic" to be decrypted, indicating both inbound and outbound scenarios. Therefore, it's crucial to have a solution capable of decrypting both inbound traffic and outbound traffic, whether it's directed towards trusted or untrusted destinations. In this context, a decryption profile stands out as the most comprehensive solution. By attaching a decryption profile to the decryption policy rule, it ensures that all traffic matching the rule undergoes decryption, regardless of whether it's inbound or outbound, and regardless of the trust status of the destination server's certificate. Hence, considering the broad scope of traffic mentioned in the question, Option A, which emphasizes the importance of a decryption profile, appears to be the most appropriate choice.
upvoted 1 times
...
cerifyme85
9 months, 3 weeks ago
Selected Answer: A
answer is A
upvoted 1 times
...
Marshpillowz
10 months, 3 weeks ago
Selected Answer: D
D appears to be correct
upvoted 1 times
...
Whizdhum
1 year ago
Answer is D. At a minimum, you need a Forward Trust certificate to present to clients when a trusted CA has signed the server certificate. Although Decryption Policies are optional, it's a best practice to include them to prevent allowing questionable traffic on the network.
upvoted 1 times
...
Knowledge33
1 year, 6 months ago
Selected Answer: D
I just did it on my PAN. The decryption profile is not mandatory. It's optional, but the certificate with "forward trust" is mandatory.
upvoted 4 times
...
ConfuzedOne
1 year, 6 months ago
Selected Answer: D
I think this question / answer set must be entered incorrectly - the question/answer pairing itself is not complete - we need to know whether we're talking inbound SSL decryption or outbound SSL forward Proxy.... If it's inbound SSL decryption then then options B and D are completly bunk. and as pointed out in some other comments, Palo's official documentation states decryption profiles are optional, but the question is about what is required. NO RIGHT ANSWER HERE If this is for outbound SSL Forward Proxy, again, Palo's documentation says the profile is optional, so answers A and C are completely bunk. Answer B completely defeats the purpose of the use of trusted and untrusted certificates - you need 2 certs, 1 trusted and 1 not trusted, so you would not have the same cert be both trusted and not trusted. That leaves option D - There must be a certificate with only the Forward Trust option selected... so if there's anything close to right, it seems Option D is it.
upvoted 1 times
...
spitfire698
1 year, 7 months ago
D is correct. you can create a decryption policy (ssl forward proxy) and leave the profile field in the policy on none. it will allow it, and traffic will still be decrypted. (though I doubt it's a good idea to do it like that since at best in that case it will use the default profile which allows way too much, at worst is just doesn't apply any limitations at all)
upvoted 1 times
...
GohanF2
1 year, 10 months ago
A and D can be both true. However, I will go this time for D. A is for additional granular control and it's not necessary for a regular SSL decryption rule . However, for deploying a regular SSL decryption rule, we need a trusted CA certificate to forward. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-overview
upvoted 1 times
...
John105
1 year, 10 months ago
I think A is correct, because D in the certificate option is not only 1 option possible to select as in point D. In addition to Forward Trust Certificate it possible options is Trusted Root CA. Therefore, A is correct Answer.
upvoted 1 times
...
mohr22
1 year, 10 months ago
A : After you create a decryption profile, attach it to a decryption policy rule; the firewall then enforces the decryption profile settings on traffic that matches the decryption policy rule.
upvoted 1 times
...
news088
1 year, 10 months ago
I think D is correct. The question come with must. To decrypt a decryption profile is not a requisite. But a certificate can only have one option trust or untrust not both. This is why D is the correct one.
upvoted 1 times
...
djedeen
1 year, 11 months ago
A: Configuring SSL Inbound Inspection includes: Installing the targeted server certificate on the firewall. Creating an SSL Inbound Inspection Decryption policy rule. Applying a Decryption profile to the policy rule.
upvoted 1 times
...
beikenes
1 year, 11 months ago
Selected Answer: A
A seems to be the most correct one
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago