nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #124

An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving "Your con

Sign in or unlock NGFW-ENGINEER to reveal the answer and full explanation for question #124. The question stem and answer options stay visible for context.

Configure and Manage Firewall Security Features

Question

An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving "Your connection is not private" browser errors for all external websites. What is the most likely cause of these widespread certificate errors?

Options

  • AThe decryption policy is configured with a "no-decrypt" action, which causes browsers to reject the
  • BThe external websites are using TLS 1.3, which cannot be decrypted by the firewall without a
  • CThe firewall's forward untrust certificate has expired, preventing it from identifying untrusted sites.
  • DThe firewall's self-signed CA certificate is not deployed to the trusted certificate store on client

Unlock NGFW-ENGINEER to see the answer

You've previewed enough free NGFW-ENGINEER questions. Unlock NGFW-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#SSL Decryption#Certificate Trust#Self-signed CA#Forward Proxy
Full NGFW-ENGINEER Practice