PCNSA · Question #176
Which option is part of the content inspection process?
The correct answer is C. SSL Proxy re-encrypt. On Palo Alto Networks firewalls, the content inspection engine (Content-ID) processes decrypted traffic. When SSL/TLS traffic is subject to SSL Forward Proxy or SSL Inbound Inspection, the firewall decrypts, inspects, and then re-encrypts the traffic before forwarding it - this…
Question
Which option is part of the content inspection process?
Options
- APacket forwarding process
- BIPsec tunnel encryption
- CSSL Proxy re-encrypt
- DPacket egress process
How the community answered
(29 responses)- A3% (1)
- B7% (2)
- C90% (26)
Explanation
On Palo Alto Networks firewalls, the content inspection engine (Content-ID) processes decrypted traffic. When SSL/TLS traffic is subject to SSL Forward Proxy or SSL Inbound Inspection, the firewall decrypts, inspects, and then re-encrypts the traffic before forwarding it - this SSL Proxy re-encryption (C) is an integral step within the content inspection pipeline. Packet forwarding (A) and packet egress (D) are separate processing stages that occur outside of content inspection. IPsec tunnel encryption (B) is a VPN function handled by a different processing path and is unrelated to content inspection.
Topics
Community Discussion
No community discussion yet for this question.