nerdexam
Palo_Alto_Networks

PCNSE · Question #353

In a firewall, which three decryption methods are valid? (Choose three )

The correct answer is A. SSL Inbound Inspection D. Decryption Mirror E. SSH Proxy. PAN-OS supports the following decryption methods: (A) SSL Inbound Inspection - used to decrypt inbound SSL/TLS traffic to internal servers where the firewall holds the server's private key; (D) Decryption Mirror - copies decrypted traffic to an out-of-band interface for…

Submitted by anjalisingh· Apr 18, 2026Core Concepts

Question

In a firewall, which three decryption methods are valid? (Choose three )

Options

  • ASSL Inbound Inspection
  • BSSL Outbound Proxyless Inspection
  • CSSL Inbound Proxy
  • DDecryption Mirror
  • ESSH Proxy

How the community answered

(61 responses)
  • A
    92% (56)
  • B
    5% (3)
  • C
    3% (2)

Explanation

PAN-OS supports the following decryption methods: (A) SSL Inbound Inspection - used to decrypt inbound SSL/TLS traffic to internal servers where the firewall holds the server's private key; (D) Decryption Mirror - copies decrypted traffic to an out-of-band interface for forensic or DLP purposes; and (E) SSH Proxy - intercepts and inspects SSH tunnel traffic. The primary forward-proxy method is 'SSL Forward Proxy' (not listed as a choice here). 'SSL Outbound Proxyless Inspection' (B) does not exist as a PAN-OS decryption method. 'SSL Inbound Proxy' (C) is not a valid PAN-OS decryption type name - the correct term is SSL Inbound Inspection.

Topics

#Decryption Methods#SSL/TLS Inspection#SSH Inspection#Palo Alto Firewall Features

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice