PSE-STRATA · Question #211
Which two actions should be taken prior to installing a decryption policy on an NGFW? (Choose two.)
The correct answer is A. Ensure throughput will not be an issue. B. Determine whether local / regional decryption laws apply. Before deploying a decryption policy on an NGFW, you must assess throughput capacity (A) because SSL/TLS inspection is computationally expensive - it can significantly degrade firewall performance, so verifying the hardware can handle the added load is essential pre-deployment…
Question
Which two actions should be taken prior to installing a decryption policy on an NGFW? (Choose two.)
Options
- AEnsure throughput will not be an issue.
- BDetermine whether local / regional decryption laws apply.
- CDeploy decryption settings all at one time.
- DInclude all traffic types in decryption policy.
How the community answered
(36 responses)- A75% (27)
- C8% (3)
- D17% (6)
Explanation
Before deploying a decryption policy on an NGFW, you must assess throughput capacity (A) because SSL/TLS inspection is computationally expensive - it can significantly degrade firewall performance, so verifying the hardware can handle the added load is essential pre-deployment. You must also check local and regional decryption laws (B) because intercepting encrypted traffic - even for security purposes - may violate privacy regulations in certain jurisdictions (e.g., healthcare data, financial communications, or country-specific privacy laws).
C is wrong because best practice is a phased rollout, not deploying all decryption settings at once - a gradual approach lets you monitor impact and catch issues before they affect all traffic. D is wrong because decrypting all traffic types is inadvisable; sensitive categories (banking, healthcare, HR systems) should typically be excluded for legal, ethical, and performance reasons.
Memory tip: Think "Assess before you Build" - Always check Appliance throughput and Boundaries (legal) before flipping on decryption. If you mix up C or D, remember that "all at once" and "all traffic" are almost always wrong in security policy - phased and selective is the mantra.
Community Discussion
No community discussion yet for this question.