PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 575


Which two actions must an engineer take to configure SSL Forward Proxy decryption? (Choose two.)

Show Answer
Correct Answer: BC

To configure SSL Forward Proxy decryption, an engineer must configure SSL decryption rules and define a Forward Trust Certificate. The SSL decryption rules are necessary to set the criteria for when and how decryption occurs. The Forward Trust Certificate is crucial because it establishes trust with clients, allowing the proxy to decrypt and inspect SSL traffic. While configuring a decryption profile can enhance security by specifying protocols and algorithms, it is not strictly required to set up basic SSL Forward Proxy decryption.

Discussion

10 comments
Sign in to comment
Kaifus
Jan 23, 2024

On the 1/23/24 exam

d34a5ebOptions: BC
Jan 18, 2024

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-forward-proxy Although Decryption profiles are optional, it is a best practice to include a Decryption profile with each Decryption policy rule to prevent weak, vulnerable protocols and algorithms from allowing questionable traffic on your network.

tonjaOptions: BC
Mar 17, 2024

The questuion qis "Which two actions must " Decryption profile is optional. So correct answer is B a and C

weze1336Options: BC
Jun 10, 2024

on exam 06/10/2024

franko_72Options: BC
Jan 3, 2024

Answer C, B I have just tested in lab, you def need SSL Forward Trust Cert and you configure a Decryption Policy Rule under Policies >> Decryption >> Add with Source Zone, Destination Zone and Options of SSL Forward Proxy.

cx777oOptions: BC
Jan 8, 2024

Answer BC: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/configure-ssl-forward-proxy --> there it states that a forward trust cert as well as a decryption rule are necessary, a decryption profile is optional

tamaster22Options: AB
Jan 8, 2024

Profile is not mandatory.

MarshpillowzOptions: BC
Feb 4, 2024

B and C correct

jens23Options: BC
Mar 7, 2024

You don't need to configure decryption profile, there is already one predefined (default) and this decryption profile you don't even need to apply in a decryption policy rule.

hdrnzienlaoroljolOptions: BC
Mar 11, 2024

B and C correct