PCNSE · Question #396
What are three types of Decryption Policy rules? (Choose three.)
The correct answer is A. SSL Inbound Inspection B. SSH Proxy C. SSL Forward Proxy. PAN-OS supports three Decryption Policy rule types: (A) SSL Inbound Inspection - used to decrypt and inspect inbound SSL/TLS traffic destined for internal servers (e.g., a web server in the DMZ); the firewall uses the server's actual private key. (B) SSH Proxy - intercepts and…
Question
What are three types of Decryption Policy rules? (Choose three.)
Options
- ASSL Inbound Inspection
- BSSH Proxy
- CSSL Forward Proxy
- DDecryption Broker
- EDecryption Mirror
How the community answered
(23 responses)- A87% (20)
- D9% (2)
- E4% (1)
Explanation
PAN-OS supports three Decryption Policy rule types: (A) SSL Inbound Inspection - used to decrypt and inspect inbound SSL/TLS traffic destined for internal servers (e.g., a web server in the DMZ); the firewall uses the server's actual private key. (B) SSH Proxy - intercepts and inspects SSH tunnels to detect tunneled protocols or data exfiltration over SSH. (C) SSL Forward Proxy - the most common type; decrypts outbound SSL/TLS traffic from internal users to the internet by acting as a man-in-the-middle using a re-signing CA certificate. (D) Decryption Broker and (E) Decryption Mirror are features/capabilities within the decryption framework, not Decryption Policy rule types. Decryption Broker forwards decrypted traffic to third-party tools, and Decryption Mirror copies decrypted traffic to a capture device - neither is a rule type you select in the Decryption policy.
Topics
Community Discussion
No community discussion yet for this question.