nerdexam
Palo_Alto_Networks

PCNSE · Question #255

Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?

The correct answer is B. No prerequisites are required.. Configuring SSH Proxy does not require certificates and the key used to decrypt SSH sessions is generated automatically on the firewall during boot up. With SSH decryption enabled, all SSH traffic identified by the policy is decrypted and identified as either regular SSH traffic

Submitted by minji_kr· Apr 18, 2026Deploy and Configure

Question

Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?

Options

  • ABoth SSH keys and SSL certificates must be generated.
  • BNo prerequisites are required.
  • CSSH keys must be manually generated.
  • DSSL certificates must be generated.

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    90% (19)
  • C
    5% (1)

Explanation

Configuring SSH Proxy does not require certificates and the key used to decrypt SSH sessions is generated automatically on the firewall during boot up. With SSH decryption enabled, all SSH traffic identified by the policy is decrypted and identified as either regular SSH traffic or as SSH tunneled traffic. SSH tunneled traffic is blocked and restricted according to the profiles configured on the firewall. Traffic is re-encrypted as it exits the firewall. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssh-proxy

Topics

#SSH Proxy Decryption#Decryption Policy#Policy Creation Prerequisites#Palo Alto Networks Security Features

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice