PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 89


Which two benefits come from assigning a Decryption Profile to a Decryption policy rule with a `No Decrypt` action? (Choose two.)

Show Answer
Correct Answer: AD

Assigning a Decryption Profile to a Decryption policy rule with a 'No Decrypt' action offers specific benefits. One of these is blocking sessions with expired certificates, as expired certificates might indicate compromised security or misconfigured systems. Another benefit includes blocking sessions with untrusted issuers, ensuring that only certificates from known and trusted sources are allowed. This action improves overall network security without decrypting the traffic.

Discussion

10 comments
Sign in to comment
djedeenOptions: AC
Jan 9, 2023

A,C,D are all correct for this question: Depending on your needs, create Decryption profiles to: Block sessions based on certificate status, including blocking sessions with >>>expired certificates, >>>untrusted issuers, unknown certificate status, certificate status check timeouts, and certificate extensions. Block sessions with >>>unsupported versions and cipher suites, and that require using client authentication.

studycertsOptions: AD
Nov 27, 2022

Not sure about this question, as the URL below says this: Block sessions based on certificate status, including blocking sessions with expired certificates, untrusted issuers, unknown certificate status, certificate status check timeouts, and certificate extensions. Block sessions with unsupported versions and cipher suites, and that require using client authentication. So theoretically A, C, and D seem to be correct, but we only need to chose 2?

dians
Dec 5, 2022

C is not correct because of the action "No decrypt", it's not relevant to talk about cipher suites in this case because there is no decryption

obatel
Dec 9, 2022

The "No decrypt" in the question does not make C incorrect. Unsupported cipher is also a benefit of the decryption profile. There is a BitTorrent question earlier that a decryption profile due to unsupported cipher was given as the answer.

markeloff23
Mar 15, 2023

yes, see bittorrent question

Techn
Jun 20, 2023

exactly, https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-concepts/no-decryption-decryption-profile

TAKUM1yOptions: AD
Sep 22, 2022

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-profile

lildevilOptions: AC
Jun 10, 2023

A C & D are correct based on https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-profile

firebOptions: AD
Oct 18, 2022

A & D are the correct options.

NawdaOptions: CD
Sep 14, 2023

V as well

Nawda
Sep 14, 2023

I meant c

MarshpillowzOptions: AD
Jan 23, 2024

A and D correct

PnosukeOptions: AD
Jan 31, 2024

A and D are correct. "No Decryption" is the Keyword of this question. There are following 2 items in the Server Certificate Verification in the No Decryption configuration. - Block sessions with expired certificates - Block sessions with untrusted issuers

PnosukeOptions: AD
Jan 31, 2024

Here is the documentation for A and D. https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/decryption/decryption-concepts/no-decryption-decryption-profile#id185BA08H0PP

kambataOptions: AC
Jul 3, 2024

A and C, checked on an actual firewall, those are the only settings in NO DECRYPT.