PCNSE · Question #353
In a firewall, which three decryption methods are valid? (Choose three )
The correct answer is A. SSL Inbound Inspection D. Decryption Mirror E. SSH Proxy. PAN-OS supports the following decryption methods: (A) SSL Inbound Inspection - used to decrypt inbound SSL/TLS traffic to internal servers where the firewall holds the server's private key; (D) Decryption Mirror - copies decrypted traffic to an out-of-band interface for…
Question
In a firewall, which three decryption methods are valid? (Choose three )
Options
- ASSL Inbound Inspection
- BSSL Outbound Proxyless Inspection
- CSSL Inbound Proxy
- DDecryption Mirror
- ESSH Proxy
How the community answered
(61 responses)- A92% (56)
- B5% (3)
- C3% (2)
Explanation
PAN-OS supports the following decryption methods: (A) SSL Inbound Inspection - used to decrypt inbound SSL/TLS traffic to internal servers where the firewall holds the server's private key; (D) Decryption Mirror - copies decrypted traffic to an out-of-band interface for forensic or DLP purposes; and (E) SSH Proxy - intercepts and inspects SSH tunnel traffic. The primary forward-proxy method is 'SSL Forward Proxy' (not listed as a choice here). 'SSL Outbound Proxyless Inspection' (B) does not exist as a PAN-OS decryption method. 'SSL Inbound Proxy' (C) is not a valid PAN-OS decryption type name - the correct term is SSL Inbound Inspection.
Topics
Community Discussion
No community discussion yet for this question.