nerdexam
Palo_Alto_Networks

PCNSE7 · Question #41

How is the Forward Untrust Certificate used?

The correct answer is C. It is presented to clients when the server they are connecting to is signed by a certificate authority. Though a single certificate can be used for both Forward Trust and Forward Untrust, creating a separate certificate specifically for Untrust (which must be generated as a CA) allows for easy differentiation of a valid certificate/trust error as the Palo Alto Networks device…

Configure and Deploy

Question

How is the Forward Untrust Certificate used?

Options

  • AIt issues certificates encountered on the Untrust security zone when clients attempt to connect to
  • BIt is used when web servers request a client certificate.
  • CIt is presented to clients when the server they are connecting to is signed by a certificate authority
  • DIt is used for Captive Portal to identify unknown users.

How the community answered

(49 responses)
  • A
    14% (7)
  • B
    6% (3)
  • C
    76% (37)
  • D
    4% (2)

Explanation

Though a single certificate can be used for both Forward Trust and Forward Untrust, creating a separate certificate specifically for Untrust (which must be generated as a CA) allows for easy differentiation of a valid certificate/trust error as the Palo Alto Networks device proxies the secure Verify the CA to be blocked, keeping in mind that doing so blocks access to all sites issued by https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Prevent-Access-to-Encrypted- Websites-Based-on-Certificate/ta-p/57585

Topics

#SSL inspection#forward untrust certificate#SSL decryption#certificate management

Community Discussion

No community discussion yet for this question.

Full PCNSE7 Practice