ExamGecko
Question list
Search
Search

Related questions











Question 47 - PCNSE discussion

Report
Export

A firewall is configured with SSL Forward Proxy decryption and has the following four enterprise certificate authorities (Cas) i. Enterprise-Trusted-CA; which is verified as Forward Trust Certificate (The CA is also installed in the trusted store of the end-user browser and system ) ii. Enterprise-Untrusted-CA, which is verified as Forward Untrust Certificate iii. Enterprise-lntermediate-CA iv. Enterprise-Root-CA which is verified only as Trusted Root CA An end-user visits https // www example-website com/ with a server certificate Common Name (CN) www example-website com The firewall does the SSL Forward Proxy decryption for the website and the server certificate is not trusted by the firewall The end-user's browser will show that the certificate for www.example-website.com was issued by which of the following?

A.
Enterprise-Untrusted-CA which is a self-signed CA
Answers
A.
Enterprise-Untrusted-CA which is a self-signed CA
B.
Enterprise-Trusted-CA which is a self-signed CA
Answers
B.
Enterprise-Trusted-CA which is a self-signed CA
C.
Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA
Answers
C.
Enterprise-lntermediate-CA which was. in turn, issued by Enterprise-Root-CA
D.
Enterprise-Root-CA which is a self-signed CA
Answers
D.
Enterprise-Root-CA which is a self-signed CA
Suggested answer: A

Explanation:

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-forward- proxyEnterprise-Trusted-CA is installed in the trusted store of the end-user browser and system. So it should not lead to any certificate issue.

The most possible that www.example-website.com is signed by not trusted certificate authority which leads to use Enterprise-Untrusted-CA, which is not trusted as well

asked 23/09/2024
Aaaa ddsdss
22 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first