nerdexam
Palo_Alto_Networks

PCNSE · Question #396

What are three types of Decryption Policy rules? (Choose three.)

The correct answer is A. SSL Inbound Inspection B. SSH Proxy C. SSL Forward Proxy. PAN-OS supports three Decryption Policy rule types: (A) SSL Inbound Inspection - used to decrypt and inspect inbound SSL/TLS traffic destined for internal servers (e.g., a web server in the DMZ); the firewall uses the server's actual private key. (B) SSH Proxy - intercepts and…

Submitted by hassan_iq· Apr 18, 2026Deploy and Configure

Question

What are three types of Decryption Policy rules? (Choose three.)

Options

  • ASSL Inbound Inspection
  • BSSH Proxy
  • CSSL Forward Proxy
  • DDecryption Broker
  • EDecryption Mirror

How the community answered

(23 responses)
  • A
    87% (20)
  • D
    9% (2)
  • E
    4% (1)

Explanation

PAN-OS supports three Decryption Policy rule types: (A) SSL Inbound Inspection - used to decrypt and inspect inbound SSL/TLS traffic destined for internal servers (e.g., a web server in the DMZ); the firewall uses the server's actual private key. (B) SSH Proxy - intercepts and inspects SSH tunnels to detect tunneled protocols or data exfiltration over SSH. (C) SSL Forward Proxy - the most common type; decrypts outbound SSL/TLS traffic from internal users to the internet by acting as a man-in-the-middle using a re-signing CA certificate. (D) Decryption Broker and (E) Decryption Mirror are features/capabilities within the decryption framework, not Decryption Policy rule types. Decryption Broker forwards decrypted traffic to third-party tools, and Decryption Mirror copies decrypted traffic to a capture device - neither is a rule type you select in the Decryption policy.

Topics

#Decryption Policy#SSL Forward Proxy#SSL Inbound Inspection#SSH Decryption

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice