PCNSE · Question #296
Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)
The correct answer is A. Create a no-decrypt Decryption Policy rule. E. Enable the "Block sessions with untrusted issuers" setting.. You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not dec
Question
Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)
Options
- ACreate a no-decrypt Decryption Policy rule.
- BConfigure an EDL to pull IP addresses of known sites resolved from a CRL.
- CCreate a Dynamic Address Group for untrusted sites
- DCreate a Security Policy rule with vulnerability Security Profile attached.
- EEnable the "Block sessions with untrusted issuers" setting.
How the community answered
(40 responses)- A83% (33)
- B3% (1)
- C10% (4)
- D5% (2)
Explanation
You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not decrypt and inspect the session traffic. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-concepts/no- decryption-decryption-profile
Topics
Community Discussion
No community discussion yet for this question.