Exam PSE-SASE All QuestionsBrowse all questions from this exam
Question 12

Which three decryption methods are available in a security processing node (SPN)? (Choose three.)

    Correct Answer: A, C, D

    The three decryption methods available in a security processing node (SPN) are SSL Outbound Proxy, SSL Forward Proxy, and SSL Inbound Inspection. SSL Outbound Proxy and SSL Forward Proxy both handle outbound SSL traffic, allowing for inspection and decryption of this traffic. SSL Inbound Inspection deals with inbound SSL traffic, allowing inspection and decryption of traffic directed towards internal servers. SSHv2 Proxy and SSH Inbound Inspection are not commonly used for decryption in this context.

Discussion
raquinopskyOptions: BCD

Answers correct is B, C, D. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/decryption-concepts

hcirOptions: BCD

ssl forward proxy, ssl inbound inspection and sshv2

NodummyIQOptions: ACD

A. SSL Outbound Proxy C. SSL Forward Proxy D. SSL Inbound Inspection Option B, SSHv2 Proxy, is not correct because it is not one of the decryption methods available in a security processing node (SPN). While SSHv2 is a secure protocol used for encrypted communication between devices, it is not specifically designed for decryption and inspection of encrypted traffic in the context of an SPN.

veryboringitstudentOptions: BCD

Most of times the community helps me a lot, so I'm trying to help too: In this link already here: https://docs.paloaltonetworks.com/strata-cloud-manager/getting-started/manage-configuration-ngfw-and-prisma-access/security-services/decryption First it says: Strata Cloud Manager provides two types of Decryption policy rules: SSL Forward Proxy to control outbound SSL traffic and SSL Inbound Inspection to control inbound SSL traffic. But in the end - Decryption at a Glance: it mention the SSH Proxy! D) Decryption Policies—List of onboarded decryption policies. Review the policy configuration, policy type (SSL Forward Proxy, SSL Inbound Inspection, or SSH Proxy), policy action (decrypt or no-decrypt), and BPA Verdict. So, I believe the correct are B, C, D.

confusionOptions: BCD

I believe hcir is correct.

yet_another_userOptions: ACD

Agree with NodummyIQ but another misleading question (SSL outbound and forward proys are actually the same). https://docs.paloaltonetworks.com/cloud-management/administration/manage-configuration-ngfw-and-prisma-access/security-services/decryption