nerdexam
Palo_Alto_Networks

PCNSE · Question #511

A company requires that a specific set of ciphers be used when remotely managing their Palo Alto Networks appliances. Which profile should be configured in order to achieve this?

The correct answer is A. SSH Service profile. The SSH Service profile on Palo Alto Networks firewalls controls the cryptographic algorithms (ciphers, MACs, key exchange methods) permitted for SSH-based management sessions. When an organization mandates a specific cipher suite for remote management, the SSH Service profile…

Submitted by daniela_cl· Apr 18, 2026Deploy and Configure

Question

A company requires that a specific set of ciphers be used when remotely managing their Palo Alto Networks appliances. Which profile should be configured in order to achieve this?

Options

  • ASSH Service profile
  • BSSL/TLS Service profile
  • CDecryption profile
  • DCertificate profile

How the community answered

(27 responses)
  • A
    93% (25)
  • B
    4% (1)
  • C
    4% (1)

Explanation

The SSH Service profile on Palo Alto Networks firewalls controls the cryptographic algorithms (ciphers, MACs, key exchange methods) permitted for SSH-based management sessions. When an organization mandates a specific cipher suite for remote management, the SSH Service profile is the correct place to enforce this. The SSL/TLS Service profile serves a similar purpose but for HTTPS/web-based GUI access. A Decryption profile controls how the firewall handles SSL/TLS inspection of user traffic, and a Certificate profile defines how the firewall validates certificates during authentication - neither applies to management cipher enforcement.

Topics

#SSH#Management access#Cipher control#Security profiles

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice