PSE-PLATFORM · Question #315
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?
The correct answer is B. No prerequisites are required. Option B is correct because SSH proxy Decryption policies on platforms like Palo Alto Networks can be created without any prior key or certificate generation - the firewall generates the necessary SSH keys automatically when the policy is first applied to traffic, requiring no…
Question
Which prerequisite must be satisfied before creating an SSH proxy Decryption policy?
Options
- ABoth SSH keys and SSL certificates must be generated.
- BNo prerequisites are required.
- CSSH keys must be manually generated.
- DSSL certificates must be generated.
How the community answered
(66 responses)- A3% (2)
- B94% (62)
- C2% (1)
- D2% (1)
Explanation
Option B is correct because SSH proxy Decryption policies on platforms like Palo Alto Networks can be created without any prior key or certificate generation - the firewall generates the necessary SSH keys automatically when the policy is first applied to traffic, requiring no manual prerequisite steps. Option A is wrong because requiring both SSH keys and SSL certificates conflates two different decryption mechanisms (SSH Proxy and SSL/TLS decryption are separate features with different requirements). Option C is wrong because SSH keys are not manually generated by the administrator beforehand - the system handles key generation internally. Option D is wrong because SSL certificates are relevant to SSL Forward Proxy or SSL Inbound Inspection policies, not SSH proxy decryption.
Memory tip: Think "SSH = Simple Setup Here" - unlike SSL decryption (which requires CA certificate setup), SSH proxy decryption has zero prerequisites and works out of the box.
Topics
Community Discussion
No community discussion yet for this question.