ExamGecko
Question list
Search
Search

Related questions











Question 25 - PCNSC discussion

Report
Export

SSL Forward Proxy decryption is enabled on (he firewall When clients use Chrome to browse to HTTPS sites, the firewall returns the Forward Trust certificate, even when accessing websites with invalid certificates The clients need to be presented with a browser warning error with the option to proceed to websites with invalid certificates

Which two options will satisfy this requirement? (Choose two.)

A.
create a Decryption Profile with the Block sessions with expired certificates option enabled
Answers
A.
create a Decryption Profile with the Block sessions with expired certificates option enabled
B.
create a self-signed Forward Untrust enabled certificate
Answers
B.
create a self-signed Forward Untrust enabled certificate
C.
create a PKI signed Forward Unlrust enabled certificate
Answers
C.
create a PKI signed Forward Unlrust enabled certificate
D.
remove the Forward Untrust option from the Forward Trust certificate
Answers
D.
remove the Forward Untrust option from the Forward Trust certificate
Suggested answer: A, B

Explanation:

When SSL Forward Proxy decryption is enabled, and clients using Chrome need to see browser warnings for websites with invalid certificates, the following options will satisfy the requirement:

A . Create a Decryption Profile with the Block sessions with expired certificates option enabled: This option ensures that sessions with expired certificates are blocked, which will present a warning to the user.

B . Create a self-signed Forward Untrust enabled certificate: This certificate will be used for websites with invalid or untrusted certificates, prompting the browser to display a warning.

These configurations ensure that users are properly warned when accessing sites with invalid certificates, allowing them to decide whether to proceed.

Palo Alto Networks - SSL Decryption Best Practices: https://docs.paloaltonetworks.com/best-practices

Palo Alto Networks - Configuring SSL Forward Proxy: https://knowledgebase.paloaltonetworks.com

asked 23/09/2024
Danyail Storey
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first