PCNSE · Question #349
The SSL Forward Proxy decryption policy is configured. The following four certificate authority (CA) certificates are installed on the firewall. An end-user visits the untrusted website https //www…
The correct answer is B. Forward-Trust-Certificate. NOTE: Based on PAN-OS documentation, this answer appears to contain an error. In SSL Forward Proxy, when a user visits a site with an UNTRUSTED certificate (e.g., self-signed or signed by an untrusted CA), the firewall should use the Forward-Untrust Certificate (answer A) to…
Question
The SSL Forward Proxy decryption policy is configured. The following four certificate authority (CA) certificates are installed on the firewall. An end-user visits the untrusted website https //www firewall-do-not-trust-website com. Which certificate authority (CA) certificate will be used to sign the untrusted webserver certificate?
Exhibit
Options
- AForward-Untrust-Certificate
- BForward-Trust-Certificate
- CFirewall-CA
- DFirewall-Trusted-Root-CA
How the community answered
(47 responses)- A13% (6)
- B77% (36)
- C9% (4)
- D2% (1)
Explanation
NOTE: Based on PAN-OS documentation, this answer appears to contain an error. In SSL Forward Proxy, when a user visits a site with an UNTRUSTED certificate (e.g., self-signed or signed by an untrusted CA), the firewall should use the Forward-Untrust Certificate (answer A) to re-sign the generated cert - this causes the browser to display a certificate warning, alerting the user. The Forward-Trust Certificate (answer B) is reserved for sites whose certificates are validated against trusted CAs, so the browser does not show a warning. For the untrusted site in this scenario, the correct certificate used would be the Forward-Untrust Certificate (A). If this exam key lists B as correct, it is likely an error; real-world PAN-OS behavior uses the Forward-Untrust certificate for untrusted sites.
Topics
Community Discussion
No community discussion yet for this question.
