PSE-SASE · Question #16
Which three decryption methods are available in a security processing node (SPN)? (Choose three.)
The correct answer is B. SSHv2 Proxy C. SSL Forward Proxy D. SSL Inbound Inspection. A Security Processing Node (SPN) supports SSHv2 Proxy (B), SSL Forward Proxy (C), and SSL Inbound Inspection (D) as its three decryption methods. SSL Forward Proxy intercepts and decrypts outbound SSL/TLS traffic from internal users to external servers, while SSL Inbound…
Question
Which three decryption methods are available in a security processing node (SPN)? (Choose three.)
Options
- ASSL Outbound Proxy
- BSSHv2 Proxy
- CSSL Forward Proxy
- DSSL Inbound Inspection
- ESSH Inbound Inspection
How the community answered
(31 responses)- A3% (1)
- B94% (29)
- E3% (1)
Explanation
A Security Processing Node (SPN) supports SSHv2 Proxy (B), SSL Forward Proxy (C), and SSL Inbound Inspection (D) as its three decryption methods. SSL Forward Proxy intercepts and decrypts outbound SSL/TLS traffic from internal users to external servers, while SSL Inbound Inspection decrypts inbound SSL/TLS traffic destined for internal servers (using the server's private key). SSHv2 Proxy decrypts SSH version 2 sessions to inspect tunneled traffic for threats.
Why the distractors are wrong:
- A (SSL Outbound Proxy) - This is a fabricated term. The correct name for outbound SSL decryption is SSL Forward Proxy, not "Outbound Proxy."
- E (SSH Inbound Inspection) - No such method exists; SSH decryption is handled by SSHv2 Proxy, which covers both directions without a separate "inbound" variant.
Memory tip: Use the acronym FIS - Forward Proxy, Inbound Inspection, SSHv2 Proxy. If an answer choice sounds like a renamed version of a real method (e.g., "Outbound" instead of "Forward"), it's likely the distractor.
Topics
Community Discussion
No community discussion yet for this question.