nerdexam
Palo_Alto_Networks

PCNSE · Question #598

A Firewall Engineer is migrating a legacy firewall to a Palo Alto Networks firewall in order to use features like App-ID and SSL decryption. Which order of steps is best to complete this migration?

The correct answer is D. First migrate port-based rules to App-ID rules; then implement SSL decryption. Migrate from port-based to application-based Security policy rules before you create and deploy Decryption policy rules. https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best- practices/plan-ssl-decryption-best-practice-deployment

Submitted by carlos_mx· Apr 18, 2026Deploy and Configure

Question

A Firewall Engineer is migrating a legacy firewall to a Palo Alto Networks firewall in order to use features like App-ID and SSL decryption. Which order of steps is best to complete this migration?

Options

  • AFirst migrate SSH rules to App-ID; then implement SSL decryption.
  • BConfigure SSL decryption without migrating port-based security rules to App-ID rules.
  • CFirst implement SSL decryption; then migrate port-based rules to App-ID rules.
  • DFirst migrate port-based rules to App-ID rules; then implement SSL decryption.

How the community answered

(60 responses)
  • A
    2% (1)
  • B
    8% (5)
  • C
    5% (3)
  • D
    85% (51)

Explanation

Migrate from port-based to application-based Security policy rules before you create and deploy Decryption policy rules. https://docs.paloaltonetworks.com/best-practices/10-2/decryption-best-practices/decryption-best- practices/plan-ssl-decryption-best-practice-deployment

Topics

#Firewall migration#App-ID deployment#SSL decryption deployment#Security policy configuration

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice