PSE-STRATA · Question #152
Which two steps are required to configure the Decryption Broker? (Choose two.)
The correct answer is B. activate the Decryption Broker license D. enable a pair of virtual wire interfaces to forward decrypted traffic. Activating the Decryption Broker license (B) is required because the feature is not available by default and must be licensed before it can be configured. Enabling a pair of virtual wire interfaces (D) is required because the Decryption Broker uses a dedicated virtual wire…
Question
Which two steps are required to configure the Decryption Broker? (Choose two.)
Options
- Areboot the firewall to activate the license
- Bactivate the Decryption Broker license
- Cenable SSL Forward Proxy decryption
- Denable a pair of virtual wire interfaces to forward decrypted traffic
How the community answered
(39 responses)- A10% (4)
- B85% (33)
- C5% (2)
Explanation
Activating the Decryption Broker license (B) is required because the feature is not available by default and must be licensed before it can be configured. Enabling a pair of virtual wire interfaces (D) is required because the Decryption Broker uses a dedicated virtual wire interface pair to forward decrypted traffic to third-party security appliances and receive it back after inspection.
Rebooting the firewall (A) is not required to activate this license; Palo Alto licenses can be activated without a reboot. Enabling SSL Forward Proxy decryption (C) is a separate decryption profile setting and is not a prerequisite step for setting up the Decryption Broker itself -- the broker operates at a layer that handles already-decrypted traffic regardless of which decryption method is in use.
Memory tip: Think "License then Wire" -- you first need the license to unlock the feature (B), then you wire up the virtual interfaces to send and receive decrypted traffic (D). The other options describe either an unnecessary action (rebooting) or a separate feature (SSL Forward Proxy) that gets confused with the broker because both involve decryption.
Topics
Community Discussion
No community discussion yet for this question.