nerdexam
Palo_Alto_Networks

PCNSE · Question #738

An organization wants to begin decrypting guest and BYOD traffic. Which NGFW feature can be used to identify guests and BYOD users, instruct them how to download and install the CA certificate, and…

The correct answer is A. Authentication Portal. The Authentication Portal (formerly Captive Portal) is the PAN-OS feature designed to intercept HTTP/HTTPS sessions from unidentified users - such as guests or BYOD users - and redirect them to a web page. This portal page can serve multiple purposes simultaneously: it can…

Submitted by tom_us· Apr 18, 2026Deploy and Configure

Question

An organization wants to begin decrypting guest and BYOD traffic. Which NGFW feature can be used to identify guests and BYOD users, instruct them how to download and install the CA certificate, and clearly notify them that their traffic will be decrypted?

Options

  • AAuthentication Portal
  • BSSL Decryption profile
  • CSSL decryption policy
  • Dcomfort pages

How the community answered

(22 responses)
  • A
    86% (19)
  • B
    5% (1)
  • D
    9% (2)

Explanation

The Authentication Portal (formerly Captive Portal) is the PAN-OS feature designed to intercept HTTP/HTTPS sessions from unidentified users - such as guests or BYOD users - and redirect them to a web page. This portal page can serve multiple purposes simultaneously: it can prompt users to authenticate, present instructions for downloading and installing the firewall's CA certificate (needed for SSL Forward Proxy decryption), and display a legal notice or notification informing users that their traffic will be decrypted and inspected. An SSL Decryption profile (B) controls decryption behavior but doesn't notify users. An SSL decryption policy (C) defines what traffic to decrypt but has no user-facing notification. Comfort pages (D) appear during decryption but are not the mechanism for certificate installation guidance.

Topics

#Authentication Portal#SSL Decryption#BYOD#Guest Network

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice