PSE-STRATA · Question #212
Which two statements correctly describe what a Network Packet Broker does for a Palo Alto Networks NGFW? (Choose two.)
The correct answer is B. It allows SSL decryption to be offloaded to the NGFW and traffic to be decrypted only once. C. It eliminates the need for a third-party SSL decryption option, which reduces the total number of. A Network Packet Broker (NPB) acts as a central traffic aggregator and distributor, enabling the Palo Alto NGFW to perform SSL decryption once and then forward the already-decrypted traffic to other monitoring tools - eliminating redundant decryption across multiple appliances…
Question
Which two statements correctly describe what a Network Packet Broker does for a Palo Alto Networks NGFW? (Choose two.)
Options
- AIt provides a third-party SSL decryption option, which can increase the total number of third-party
- BIt allows SSL decryption to be offloaded to the NGFW and traffic to be decrypted only once.
- CIt eliminates the need for a third-party SSL decryption option, which reduces the total number of
- DIt allows SSL decryption to be offloaded to the NGFW and traffic to be decrypted multiple times.
How the community answered
(41 responses)- A17% (7)
- B73% (30)
- D10% (4)
Explanation
A Network Packet Broker (NPB) acts as a central traffic aggregator and distributor, enabling the Palo Alto NGFW to perform SSL decryption once and then forward the already-decrypted traffic to other monitoring tools - eliminating redundant decryption across multiple appliances. This is why B is correct: SSL decryption is offloaded to the NGFW and traffic is decrypted only once. C is correct because that single-decryption architecture removes the need for a separate third-party SSL decryption appliance, reducing your total tool footprint.
A is wrong because it claims the NPB adds a third-party decryption option and increases third-party tool count - the opposite of what NPBs are designed to do. D is wrong because decrypting traffic multiple times is the problem NPBs solve, not a feature they provide; redundant decryption wastes compute and is the inefficient status quo without an NPB.
Memory tip: Think "NPB = decrypt once, share everywhere." The NGFW does the hard SSL work one time, and the NPB hands off clean plaintext to all downstream tools - no third-party decryptor needed, no repeat decryption.
Community Discussion
No community discussion yet for this question.