NETSEC-GENERALIST · Question #67
Which two policies in Strata Cloud Manager (SCM) will ensure the personal data of employees remains private while enabling decryption for mobile users in Prisma Access? (Choose two.)
The correct answer is C. SSL Forward Proxy D. No Decryption. SSL Forward Proxy (C) is the decryption policy type used for mobile users (GlobalProtect clients) connecting outbound through Prisma Access - it intercepts and decrypts outbound SSL/TLS traffic so security services like Threat Prevention and URL Filtering can inspect it. No…
Question
Which two policies in Strata Cloud Manager (SCM) will ensure the personal data of employees remains private while enabling decryption for mobile users in Prisma Access? (Choose two.)
Options
- ASSH Decryption
- BSSL Inbound Inspection
- CSSL Forward Proxy
- DNo Decryption
How the community answered
(25 responses)- A12% (3)
- B8% (2)
- C80% (20)
Explanation
SSL Forward Proxy (C) is the decryption policy type used for mobile users (GlobalProtect clients) connecting outbound through Prisma Access - it intercepts and decrypts outbound SSL/TLS traffic so security services like Threat Prevention and URL Filtering can inspect it. No Decryption (D) is used in tandem to explicitly exclude categories of personal or sensitive traffic (e.g., financial, healthcare, personal email sites) from decryption, preserving employee privacy while still allowing decryption of other traffic. SSH Decryption (A) applies only to SSH tunnels, not general mobile user HTTPS traffic. SSL Inbound Inspection (B) is used to decrypt inbound traffic destined for internal servers, not for mobile user outbound sessions.
Topics
Community Discussion
No community discussion yet for this question.