nerdexam
Palo_Alto_Networks

PCNSC · Question #55

Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL forward proxy? (Choose two.)

The correct answer is C. Create a no-decrypt Decryption Policy rule. D. Enable the "Block seasons with untrusted Issuers- setting.. You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not dec

User-ID, Decryption, and Authentication

Question

Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL forward proxy? (Choose two.)

Options

  • AConfigure an EDL to pull IP Addresses of known sites resolved from a CRL.
  • BCreate a Security Policy rule with vulnerability Security Profile attached.
  • CCreate a no-decrypt Decryption Policy rule.
  • DEnable the "Block seasons with untrusted Issuers- setting.
  • EConfigure a Dynamic Address Group for untrusted sites.

How the community answered

(39 responses)
  • A
    23% (9)
  • B
    10% (4)
  • C
    62% (24)
  • E
    5% (2)

Explanation

You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not decrypt and inspect the session traffic. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-concepts/no- decryption-decryption-profile

Topics

#SSL decryption#untrusted certificates#no-decrypt policy#CRL

Community Discussion

No community discussion yet for this question.

Full PCNSC Practice