nerdexam
Palo_Alto_Networks

PCNSE · Question #298

What is the purpose of the firewall decryption broker?

The correct answer is A. decrypt SSL traffic and then send it as cleartext to a security chain of inspection tools. The Decryption Broker feature allows a Palo Alto Networks NGFW to act as a central SSL/TLS decryption point for third-party security tools. The firewall decrypts inbound or outbound SSL/TLS sessions, then forwards the plaintext traffic through a defined security chain - an…

Submitted by lucia.co· Apr 18, 2026Core Concepts

Question

What is the purpose of the firewall decryption broker?

Exhibit

PCNSE question #298 exhibit

Options

  • Adecrypt SSL traffic and then send it as cleartext to a security chain of inspection tools.
  • Bforce decryption of previously unknown cipher suites
  • Creduce SSL traffic to a weaker cipher before sending it to a security chain of inspection tools.
  • Dinspect traffic within IPsec tunnels

How the community answered

(17 responses)
  • A
    88% (15)
  • B
    6% (1)
  • C
    6% (1)

Explanation

The Decryption Broker feature allows a Palo Alto Networks NGFW to act as a central SSL/TLS decryption point for third-party security tools. The firewall decrypts inbound or outbound SSL/TLS sessions, then forwards the plaintext traffic through a defined security chain - an ordered sequence of third-party inspection appliances (e.g., DLP, IDS, malware inspection tools) that cannot decrypt SSL themselves. After the chain completes inspection, the firewall re-encrypts the traffic and forwards it to its destination. This is not about forcing weaker ciphers, inspecting IPsec, or breaking unknown cipher suites - it is purely about enabling third-party tools to inspect decrypted HTTP traffic they otherwise couldn't see.

Topics

#SSL Decryption#Decryption Broker#Traffic Inspection#Security Chaining

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice