nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #150

Which two configuration items are required when the NGFW needs to act as a decryption broker for multiple transparent bridge security chains? (Choose two.)

The correct answer is B. a unique Transparent Bridge Decryption Forwarding Profile to a single Decryption policy rule C. a unique Decryption policy rule is required per security chain. When configuring an NGFW as a decryption broker for multiple transparent bridge security chains, each chain must be governed by its own dedicated Decryption policy rule (C) so the firewall knows which traffic to direct to which chain. That rule must reference a unique…

Network Security and Threat Prevention

Question

Which two configuration items are required when the NGFW needs to act as a decryption broker for multiple transparent bridge security chains? (Choose two.)

Options

  • Adedicated pair of decryption forwarding interfaces required per security chain
  • Ba unique Transparent Bridge Decryption Forwarding Profile to a single Decryption policy rule
  • Ca unique Decryption policy rule is required per security chain
  • Da single pair of decryption forwarding interfaces

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    79% (37)
  • D
    15% (7)

Explanation

When configuring an NGFW as a decryption broker for multiple transparent bridge security chains, each chain must be governed by its own dedicated Decryption policy rule (C) so the firewall knows which traffic to direct to which chain. That rule must reference a unique Transparent Bridge Decryption Forwarding Profile (B), because the profile is what maps the policy to the specific forwarding interfaces used by that chain - without a distinct profile per rule, the firewall cannot differentiate between chains.

Option A is wrong because a dedicated pair of decryption forwarding interfaces is not required for every security chain; interface pairs can be shared or reused across chains. Option D is wrong not because one pair is impossible, but because stating "a single pair" misrepresents the actual required configuration item - the key requirement is the forwarding profile and policy rule pairing, not a hard limit on interface pairs.

Memory tip: Think of it as "one chain, one rule, one profile." Each security chain needs its own policy rule (C) and its own profile tied to that rule (B) - the two always travel together.

Topics

#SSL/TLS Decryption#Transparent Bridging#Decryption Policies#Forwarding Profiles

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice