nerdexam
Palo_Alto_Networks

PCNSE · Question #240

An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance. Which interface type and license feature are n

The correct answer is D. Decryption Mirror interface with the associated Decryption Port Mirror license. Decryption port mirroring allows you to copy decrypted traffic from a firewall and then send it to a traffic collection tool, such as NetWitness or Solera. Decryption mirroring requires a Decryption Port Mirror license. This license is free of change and you can activate it throu

Submitted by lars.no· Apr 18, 2026Deploy and Configure

Question

An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance. Which interface type and license feature are necessary to meet the requirement?

Options

  • ADecryption Mirror interface with the Threat Analysis license
  • BVirtual Wire interface with the Decryption Port Export license
  • CTap interface with the Decryption Port Mirror license
  • DDecryption Mirror interface with the associated Decryption Port Mirror license

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    5% (2)
  • D
    88% (35)

Explanation

Decryption port mirroring allows you to copy decrypted traffic from a firewall and then send it to a traffic collection tool, such as NetWitness or Solera. Decryption mirroring requires a Decryption Port Mirror license. This license is free of change and you can activate it through the customer https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-decryption-

Topics

#Decryption Mirroring#NGFW Interfaces#Traffic Export#Licensing

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice