PCNSC · Question #55
Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL forward proxy? (Choose two.)
The correct answer is C. Create a no-decrypt Decryption Policy rule. D. Enable the "Block seasons with untrusted Issuers- setting.. You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not dec
Question
Which two action would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL forward proxy? (Choose two.)
Options
- AConfigure an EDL to pull IP Addresses of known sites resolved from a CRL.
- BCreate a Security Policy rule with vulnerability Security Profile attached.
- CCreate a no-decrypt Decryption Policy rule.
- DEnable the "Block seasons with untrusted Issuers- setting.
- EConfigure a Dynamic Address Group for untrusted sites.
How the community answered
(39 responses)- A23% (9)
- B10% (4)
- C62% (24)
- E5% (2)
Explanation
You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not decrypt and inspect the session traffic. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-concepts/no- decryption-decryption-profile
Topics
Community Discussion
No community discussion yet for this question.