nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #211

Which two actions should be taken prior to installing a decryption policy on an NGFW? (Choose two.)

The correct answer is A. Ensure throughput will not be an issue. B. Determine whether local / regional decryption laws apply. Before deploying a decryption policy on an NGFW, you must assess throughput capacity (A) because SSL/TLS inspection is computationally expensive - it can significantly degrade firewall performance, so verifying the hardware can handle the added load is essential pre-deployment…

Question

Which two actions should be taken prior to installing a decryption policy on an NGFW? (Choose two.)

Options

  • AEnsure throughput will not be an issue.
  • BDetermine whether local / regional decryption laws apply.
  • CDeploy decryption settings all at one time.
  • DInclude all traffic types in decryption policy.

How the community answered

(36 responses)
  • A
    75% (27)
  • C
    8% (3)
  • D
    17% (6)

Explanation

Before deploying a decryption policy on an NGFW, you must assess throughput capacity (A) because SSL/TLS inspection is computationally expensive - it can significantly degrade firewall performance, so verifying the hardware can handle the added load is essential pre-deployment. You must also check local and regional decryption laws (B) because intercepting encrypted traffic - even for security purposes - may violate privacy regulations in certain jurisdictions (e.g., healthcare data, financial communications, or country-specific privacy laws).

C is wrong because best practice is a phased rollout, not deploying all decryption settings at once - a gradual approach lets you monitor impact and catch issues before they affect all traffic. D is wrong because decrypting all traffic types is inadvisable; sensitive categories (banking, healthcare, HR systems) should typically be excluded for legal, ethical, and performance reasons.

Memory tip: Think "Assess before you Build" - Always check Appliance throughput and Boundaries (legal) before flipping on decryption. If you mix up C or D, remember that "all at once" and "all traffic" are almost always wrong in security policy - phased and selective is the mantra.

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice