exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 288 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 288
Topic #: 1
[All PCNSE Questions]

An engineer must configure the Decryption Broker feature. Which Decryption Broker security chain supports bi-directional traffic flow?

  • A. Layer 2 security chain
  • B. Layer 3 security chain
  • C. Transparent Bridge security chain
  • D. Transparent Proxy security chain
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
archer3129871
1 month, 1 week ago
Answer is B ================================== The Decryption Broker feature supports two types of security chain networks: Layer 3 security chains and Transparent Bridge security chains. You can configure the firewall to direct traffic through the security chain either unidirectionally or bidirectionally1. **When it comes to bi-directional traffic flow, the Layer 3 security chain is the one you’re looking for. Let me provide more details about how it works: The firewall uses the Primary Interface dedicated to decryption forwarding to forward both inbound and outbound sessions to the first security chain device. The last security chain device forwards both inbound and outbound sessions back to the firewall2.
upvoted 1 times
...
Whizdhum
7 months ago
Answers are B, C. The bidirectional flow option is available for both security chain types. Your network topology determines whether to use unidirectional or bidirectional flows. The performance is approximately the same using either method.
upvoted 2 times
...
GohanF2
1 year, 5 months ago
nasty question. both B and C are valid
upvoted 1 times
...
mz101
1 year, 7 months ago
Other than B, looks like that C is correct as well based on following: "Set the Flow Direction for decrypted traffic the firewall forwards: Unidirectional or Bidirectional." https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/decryption-broker/decryption-broker-configure-with-transparent-bridge
upvoted 1 times
...
TAKUM1y
1 year, 8 months ago
Selected Answer: B
B !! : https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/decryption/decryption-broker/security-chain-layer-3-guidelines
upvoted 2 times
...
Alen
1 year, 8 months ago
B and C are correct here as stated above. Also Decryption broker is now called Network packet broker https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-new-features/networking-features/network-packet-broker
upvoted 3 times
...
mizuno92
1 year, 9 months ago
Layer 3 and Transparent Bridge support Bidirectional
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago