PCNSE · Question #556
An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)
The correct answer is A. URL categories B. source users C. source and destination IP addresses. PAN-OS SSL Decryption policy rules support several match criteria: URL categories (A), source users (B), and source/destination IP addresses (C) are all valid parameters. App-ID (D) cannot be used as a match criterion in SSL decryption rules because the application identity…
Question
An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)
Options
- AURL categories
- Bsource users
- Csource and destination IP addresses
- DApp-ID
- EGlobalProtect HIP
How the community answered
(28 responses)- A89% (25)
- D7% (2)
- E4% (1)
Explanation
PAN-OS SSL Decryption policy rules support several match criteria: URL categories (A), source users (B), and source/destination IP addresses (C) are all valid parameters. App-ID (D) cannot be used as a match criterion in SSL decryption rules because the application identity cannot be determined until after the session is decrypted - using it as a pre-decryption match criterion creates a logical impossibility. GlobalProtect HIP profiles (E) are not valid match parameters within SSL decryption policies.
Topics
Community Discussion
No community discussion yet for this question.