exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 57 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 57
Topic #: 1
[All PCNSE Questions]

Refer to the exhibit.

Which certificates can be used as a Forward Trust certificate?

  • A. Certificate from Default Trust Certificate Authorities
  • B. Domain Sub-CA
  • C. Forward-Trust
  • D. Domain-Root-Cert
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Breyarg
Highly Voted 3 years, 1 month ago
wouldn't the only correct answer be B? Must be a CA to be used. must have private key also. can be a root but doesnt have to be.... so that only leaves B as correct answer? anyone? as far as i know you cant use public certs for decryption? so cant be A
upvoted 11 times
NHANTON
3 years ago
yes, CA and the key is mandatory
upvoted 4 times
...
GivemeMoney
3 years ago
Should be D. Domain-Root-Cert, the usage "Trusted Root CA Certificate" is the one that is going to be used.
upvoted 2 times
Knowledge33
1 year, 7 months ago
There is no key on the D. The question is "can be used", not "is used". We only need to click on the certificate, then check the box " Forward trust Certificate". Only B is correct.
upvoted 2 times
...
...
Pretorian
2 years, 5 months ago
You are correct. You cannot use certificates from well known third party CA's (like GoDaddy, etc) for decryption. The more elegant approach for SSL Forward Proxy and the easiest by far is a to use a domain CA because automatically all domain joined machines will trust those certificates, overcoming the challenge of distribution of the decryption certificate.
upvoted 3 times
...
...
CarlosDV06
Most Recent 2 months, 2 weeks ago
B can be used. It's true that its not checked as trusted root, but its parent cert is (domain root cert).
upvoted 1 times
...
Marshpillowz
12 months ago
Selected Answer: B
Correct answer is B
upvoted 1 times
...
JRKhan
1 year ago
Selected Answer: B
B is correct as both CA and Key options need to be selected/enabled.
upvoted 1 times
...
Gabranch
1 year, 1 month ago
Selected Answer: B
Aside from requiring it to be a CA, you'll notice that answer C uses a hyphen but the cert name has an underscore.
upvoted 2 times
...
PaloSteve
1 year, 6 months ago
My vote is for C. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/configure-ssl-forward-proxy In Step 4 of the Use a self-signed certificate as the Forward Trust certificate, which is titled "Generate new subordinate CA certificates for each firewall" it follows with 5. "Click the new certificate to modify it and click the Forward Trust Certificate checkbox to configure the certificate as the Forward Trust Certificate". The CA box is only necessary to be checked for the Intermediate key. It is the cert created from the Intermediate CA that is used as the Forward Trust cert.
upvoted 2 times
...
Knowledge33
1 year, 7 months ago
Selected Answer: B
There is no key on the D. The question is "can be used", not "is used". We only need to click on the certificate, then check the box " Forward trust Certificate". Only B is correct.
upvoted 1 times
...
KKQQ12345
2 years, 5 months ago
This is not a valid question. Forward-Trusted Cert has to be configured, otherwise you can't even commit.
upvoted 2 times
...
KKQQ12345
2 years, 5 months ago
Selected Answer: D
B should be wrong because their usage is empty AC does not have CA
upvoted 1 times
Knowledge33
1 year, 7 months ago
There is no key on the D. The question is "can be used", not "is used". We only need to click on the certificate, then check the box " Forward trust Certificate". Only B is correct.
upvoted 2 times
...
...
UFanat
2 years, 6 months ago
Selected Answer: B
B is a correct one
upvoted 1 times
...
Meira088
2 years, 7 months ago
Selected Answer: B
B is correct answer
upvoted 2 times
...
1Adrian1
2 years, 9 months ago
B is correct
upvoted 2 times
...
NHANTON
3 years ago
Selected Answer: B
B is correct answer
upvoted 4 times
poiuytr
2 years, 9 months ago
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMNKCA4&lang=en_US%E2%80%A9
upvoted 4 times
...
...
NHANTON
3 years ago
B is correct answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago