nerdexam
Palo_Alto_Networks

NETSEC-GENERALIST · Question #67

Which two policies in Strata Cloud Manager (SCM) will ensure the personal data of employees remains private while enabling decryption for mobile users in Prisma Access? (Choose two.)

The correct answer is C. SSL Forward Proxy D. No Decryption. SSL Forward Proxy (C) is the decryption policy type used for mobile users (GlobalProtect clients) connecting outbound through Prisma Access - it intercepts and decrypts outbound SSL/TLS traffic so security services like Threat Prevention and URL Filtering can inspect it. No…

Threat Prevention and Decryption

Question

Which two policies in Strata Cloud Manager (SCM) will ensure the personal data of employees remains private while enabling decryption for mobile users in Prisma Access? (Choose two.)

Options

  • ASSH Decryption
  • BSSL Inbound Inspection
  • CSSL Forward Proxy
  • DNo Decryption

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    8% (2)
  • C
    80% (20)

Explanation

SSL Forward Proxy (C) is the decryption policy type used for mobile users (GlobalProtect clients) connecting outbound through Prisma Access - it intercepts and decrypts outbound SSL/TLS traffic so security services like Threat Prevention and URL Filtering can inspect it. No Decryption (D) is used in tandem to explicitly exclude categories of personal or sensitive traffic (e.g., financial, healthcare, personal email sites) from decryption, preserving employee privacy while still allowing decryption of other traffic. SSH Decryption (A) applies only to SSH tunnels, not general mobile user HTTPS traffic. SSL Inbound Inspection (B) is used to decrypt inbound traffic destined for internal servers, not for mobile user outbound sessions.

Topics

#SSL Decryption#Privacy Policies#Prisma Access#Security Policy

Community Discussion

No community discussion yet for this question.

Full NETSEC-GENERALIST Practice