PSE-STRATA · Question #150
Which two configuration items are required when the NGFW needs to act as a decryption broker for multiple transparent bridge security chains? (Choose two.)
The correct answer is B. a unique Transparent Bridge Decryption Forwarding Profile to a single Decryption policy rule C. a unique Decryption policy rule is required per security chain. When configuring an NGFW as a decryption broker for multiple transparent bridge security chains, each chain must be governed by its own dedicated Decryption policy rule (C) so the firewall knows which traffic to direct to which chain. That rule must reference a unique…
Question
Which two configuration items are required when the NGFW needs to act as a decryption broker for multiple transparent bridge security chains? (Choose two.)
Options
- Adedicated pair of decryption forwarding interfaces required per security chain
- Ba unique Transparent Bridge Decryption Forwarding Profile to a single Decryption policy rule
- Ca unique Decryption policy rule is required per security chain
- Da single pair of decryption forwarding interfaces
How the community answered
(47 responses)- A6% (3)
- B79% (37)
- D15% (7)
Explanation
When configuring an NGFW as a decryption broker for multiple transparent bridge security chains, each chain must be governed by its own dedicated Decryption policy rule (C) so the firewall knows which traffic to direct to which chain. That rule must reference a unique Transparent Bridge Decryption Forwarding Profile (B), because the profile is what maps the policy to the specific forwarding interfaces used by that chain - without a distinct profile per rule, the firewall cannot differentiate between chains.
Option A is wrong because a dedicated pair of decryption forwarding interfaces is not required for every security chain; interface pairs can be shared or reused across chains. Option D is wrong not because one pair is impossible, but because stating "a single pair" misrepresents the actual required configuration item - the key requirement is the forwarding profile and policy rule pairing, not a hard limit on interface pairs.
Memory tip: Think of it as "one chain, one rule, one profile." Each security chain needs its own policy rule (C) and its own profile tied to that rule (B) - the two always travel together.
Topics
Community Discussion
No community discussion yet for this question.