PCNSE · Question #610
An engineer is configuring secure web access (HTTPS) to a Palo Alto Networks firewall for management. Which profile should be configured to ensure that management access via web browsers is…
The correct answer is B. An SSL/TLS Service profile should be configured with a certificate assigned. An SSL/TLS Service profile defines which certificate and protocol versions are used when the firewall presents itself as an SSL/TLS server - including for HTTPS management access. Assigning a certificate signed by a trusted CA to this profile ensures browsers trust the…
Question
An engineer is configuring secure web access (HTTPS) to a Palo Alto Networks firewall for management. Which profile should be configured to ensure that management access via web browsers is encrypted with a trusted certificate?
Options
- AA Certificate profile should be configured with a trusted root CA
- BAn SSL/TLS Service profile should be configured with a certificate assigned.
- CAn Interface Management profile with HTTP and HTTPS enabled should be configured.
- DAn Authentication profile with the allow list of users should be configured.
How the community answered
(42 responses)- A7% (3)
- B88% (37)
- C2% (1)
- D2% (1)
Explanation
An SSL/TLS Service profile defines which certificate and protocol versions are used when the firewall presents itself as an SSL/TLS server - including for HTTPS management access. Assigning a certificate signed by a trusted CA to this profile ensures browsers trust the connection. A Certificate profile (A) is used for authenticating clients, not serving certificates. An Interface Management profile (C) controls which services are allowed but does not bind a specific certificate. An Authentication profile (D) defines how users authenticate, not how the TLS session is secured.
Topics
Community Discussion
No community discussion yet for this question.