Palo_Alto_NetworksPalo_Alto_Networks
NGFW-ENGINEER · Question #32
NGFW-ENGINEER Question #32: Real Exam Question with Answer & Explanation
Sign in or unlock NGFW-ENGINEER to reveal the answer and full explanation for question #32. The question stem and answer options stay visible for context.
SSL Decryption Implementation
Question
Which configuration step is required when implementing a new self-signed root certificate authority (CA) certificate for SSL decryption on a Palo Alto Networks firewall?
Options
- AImport the new subordinate CA certificate into the trust stores of all client devices.
- BSet the subordinate CA certificate as the default routing certificate for all network traffic.
- CConfigure the subordinate CA to issue certificates with indefinite validity periods.
- DDisable all existing SSL decryption rules until the new certificate is fully propagated.
Unlock NGFW-ENGINEER to see the answer
You've previewed enough free NGFW-ENGINEER questions. Unlock NGFW-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#SSL Decryption#Certificate Management#Client Trust Stores#Firewall Security