exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 210 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 210
Topic #: 1
[All PCNSE Questions]

As a best practice, which URL category should you target first for SSL decryption?

  • A. Health and Medicine
  • B. High Risk
  • C. Online Storage and Backup
  • D. Financial Services
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
davidpm
8 months, 2 weeks ago
Selected Answer: B
Plan to decrypt the riskiest traffic first (URL categories most likely to harbor malicious traffic, such as gaming or high-risk) and then decrypt more as you gain experience https://docs.paloaltonetworks.com/advanced-url-filtering/administration/configuring-url-filtering/url-filtering-best-practices
upvoted 2 times
...
TAKUM1y
1 year, 6 months ago
Selected Answer: B
https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment
upvoted 3 times
...
datz
1 year, 11 months ago
Interestingly Both seems to be BPA: This answer might have 2 answers in the exam. Create policy to decrypt the rest of the traffic by configuring SSL Forward Proxy, SSL Inbound Inspection, and SSH Proxy rules. Always decrypt the online-storage-and-backup, web-based-email, web-hosting, personal-sites-and-blogs, content-delivery-networks, and high-risk URL categories. https://docs.paloaltonetworks.com/best-practices/10-1/decryption-best-practices/decryption-best-practices/deploy-ssl-decryption-using-best-practices
upvoted 2 times
...
randomtototiti
1 year, 11 months ago
Selected Answer: C
As a best practice the high-risk category should be blocked, leaving only C
upvoted 1 times
randomtototiti
1 year, 11 months ago
Nevermind, it's B, my assumption that high-risk should be blocked as a BP was wrong
upvoted 1 times
...
...
Jheax
1 year, 12 months ago
Selected Answer: B
Plan to decrypt the riskiest traffic first (URL Categories most likely to harbor malicious traffic, such as gaming or high-risk) and then decrypt more as you gain experience. Alternatively, decrypt the URL Categories that don’t affect your business first (if something goes wrong, it won’t affect business), for example, news feeds. - Taken from PANOS10 best practices found in https://docs.paloaltonetworks.com/best-practices/10-0/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment
upvoted 2 times
...
Alen
2 years ago
Correct Answer is B. 'Online Storage and Backup is not a URL Category. "Always decrypt the online-storage-and-backup, web-based-email, web-hosting, personal-sites-and-blogs, content-delivery-networks, and high-risk URL categories. Limit SSH Proxy to administrators who manage network devices, log all SSH traffic, and configure Multi-Factor Authentication to prevent unauthorized SSH access." https://docs.paloaltonetworks.com/best-practices/10-0/decryption-best-practices/decryption-best-practices/deploy-ssl-decryption-using-best-practices
upvoted 1 times
...
Micutzu
2 years, 4 months ago
The question is referring to URL categories used as best practice for SSL decryption, and not all URL categories. Please read STEP 3 last bullet from here: https://docs.paloaltonetworks.com/best-practices/8-1/decryption-best-practices/decryption-best-practices/deploy-ssl-decryption-using-best-practices.html "If you can’t decypt everything, always decrypt the online-storage-and-backup, web-based-email, web-hosting, personal-sites-and-blogs, and content-delivery-networks URL categories."
upvoted 1 times
Micutzu
2 years, 4 months ago
Starting with PAN-OS 9.0 the paragraph include also high-risk URL categories at the end of the list.
upvoted 2 times
Mucho9999
2 years, 4 months ago
The test is based off of 10.0 High risk is the first to decrypt. https://docs.paloaltonetworks.com/best-practices/10-0/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment.html
upvoted 4 times
...
...
...
Hiwanku
2 years, 4 months ago
Online Storage and Backup is not an URL category so option B
upvoted 2 times
Micutzu
2 years, 4 months ago
please have a look here to see predefined URL categories: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5hCAC Also, on URL filtering profile we can find Online-Storage-and-Back and High-Risk, at least in PAN-OS 10.x
upvoted 1 times
...
...
Micutzu
2 years, 4 months ago
I suggest C as correct answer. https://docs.paloaltonetworks.com/best-practices/10-1/decryption-best-practices/decryption-best-practices/deploy-ssl-decryption-using-best-practices.html " . Always decrypt the online-storage-and-backup, web-based-email, web-hosting, personal-sites-and-blogs, content-delivery-networks, and high-risk URL categories. .."
upvoted 2 times
Mucho9999
2 years, 4 months ago
Tricky question. Its B, https://docs.paloaltonetworks.com/best-practices/8-1/decryption-best-practices/decryption-best-practices/plan-ssl-decryption-best-practice-deployment.html Phase in decryption. Plan to decrypt the riskiest traffic first (URL Categories most likely to harbor malicious traffic, such as gaming or high-risk)
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago