nerdexam
Palo_Alto_Networks

NETSEC-PRO · Question #57

Which two SSH Proxy decryption profile settings should be configured to enhance the company's security posture? (Choose two.)

The correct answer is A. Block sessions when certificate validation fails. C. Block connections that use non-compliant SSH versions.. Blocking non-compliant SSH versions and failing certificate validations are fundamental security Block sessions when certificate validation fails The SSH Proxy profile should block sessions that fail certificate validation to ensure that only trusted hosts are allowed. Block conn

Decryption and SSL/TLS Inspection

Question

Which two SSH Proxy decryption profile settings should be configured to enhance the company's security posture? (Choose two.)

Options

  • ABlock sessions when certificate validation fails.
  • BAllow sessions with legacy SSH protocol versions.
  • CBlock connections that use non-compliant SSH versions.
  • DAllow sessions when decryption resources are unavailable.

How the community answered

(36 responses)
  • A
    83% (30)
  • B
    11% (4)
  • D
    6% (2)

Explanation

Blocking non-compliant SSH versions and failing certificate validations are fundamental security Block sessions when certificate validation fails The SSH Proxy profile should block sessions that fail certificate validation to ensure that only trusted hosts are allowed. Block connections using non-compliant SSH versions Older SSH versions may have vulnerabilities or lack modern encryption algorithms. To enforce stronger security, block SSH sessions that use older or deprecated versions of the SSH protocol that do not comply with your security posture.

Topics

#SSH Proxy#decryption profile#certificate validation#SSH security

Community Discussion

No community discussion yet for this question.

Full NETSEC-PRO Practice