PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 278


An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)

Show Answer
Correct Answer: A,B,C,D,E

To enable SSL decryption across an environment, the SSL Decryption policy can be configured using specific parameters. Source users allow the policy to be applied based on the users generating traffic. URL categories enable the policy to categorize and decrypt traffic based on predefined URL groups, offering granular control over which websites can be accessed securely. Source and destination IP addresses help define the scope of the decryption policy by specifying which IP ranges are included or excluded in the decryption process. Therefore, the valid parameters of an SSL Decryption policy are source users, URL categories, and source and destination IP addresses.

Discussion

12 comments
Sign in to comment
nose999Options: BDE
Sep 6, 2022

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule

bimyo
Sep 22, 2022

BDE is correct, checked it in LAB

AlenOptions: BDE
Oct 5, 2022

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule

certprep2021Options: BDE
Mar 9, 2023

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEZCA0 "In particular, decryption can be based upon URL categories, source users, and source/destination IP addresses."

TAKUM1yOptions: BDE
Oct 22, 2022

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule

confusionOptions: BDE
Oct 27, 2022

BDE Src: Zone, Address, User Dst: Zone, Address Service/URL category

DenskyDenOptions: BDE
Jan 16, 2023

BDE. 1.Users—Select Source and set the Source User for whom to decrypt traffic. 2. IP addresses, address objects, and/or address groups—Select Source and/or Destination to match to traffic based on Source Address and/or the Destination Address 3. Select Service/URL Category to set the rule to match to traffic based on service

djedeenOptions: BDE
Jan 23, 2023

BDE: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/decryption/define-traffic-to-decrypt/create-a-decryption-policy-rule

[Removed]Options: BDE
Apr 27, 2023

BDE Buuuuut!!! im checking my firewall and you can put HIP at source tab.... so global protect hip should be ok i think :O

Erle1988Options: BDE
May 16, 2023

BDE is correct

findkeywordcommandOptions: BDE
Mar 22, 2024

Who decides about what is right here? You can easily check that App-ID or GlobalProtect HIP aren't in the Decryption Policy Rule options. Disappointed with this site

327c7c8Options: BDE
Mar 31, 2024

You cannot decrypt any traffic from any type of VPN, if it is GlobalProtect or AnyConnect etc. App-ID is a function in the NGFW not an element in which you can use in a oolicy. But source user, Source IP and Destination IP you can use in the SSL decrypt policy. there are HIP option you can use but this is not associated with the GlobalProtect.

ali_sh85Options: BDE
Jul 16, 2024

Decryption and Authentication policies dont use application