nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #51

What two types of traffic should you exclude from a decryption policy? (Choose two.)

The correct answer is A. All Business and regulatory traffic C. All Mutual Authentication traffic. Traffic that breaks decryption for technical reasons, such as using a pinned certificate, an incomplete certificate chain, unsupported ciphers, or mutual authentication. Traffic that you choose not to decrypt because of business, regulatory, personal, or other…

Decryption

Question

What two types of traffic should you exclude from a decryption policy? (Choose two.)

Options

  • AAll Business and regulatory traffic
  • BAll outbound traffic
  • CAll Mutual Authentication traffic
  • DAll SSL/TLS 1.3 traffic

How the community answered

(44 responses)
  • A
    77% (34)
  • B
    16% (7)
  • D
    7% (3)

Explanation

Traffic that breaks decryption for technical reasons, such as using a pinned certificate, an incomplete certificate chain, unsupported ciphers, or mutual authentication. Traffic that you choose not to decrypt because of business, regulatory, personal, or other https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/decryption-exclusions

Topics

#SSL decryption#mutual authentication#decryption exclusions#regulatory traffic

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice