ExamGecko
Question list
Search
Search

Related questions











Question 67 - PCNSE discussion

Report
Export

Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)

A.
Create a no-decrypt Decryption Policy rule.
Answers
A.
Create a no-decrypt Decryption Policy rule.
B.
Configure an EDL to pull IP addresses of known sites resolved from a CRL.
Answers
B.
Configure an EDL to pull IP addresses of known sites resolved from a CRL.
C.
Create a Dynamic Address Group for untrusted sites
Answers
C.
Create a Dynamic Address Group for untrusted sites
D.
Create a Security Policy rule with vulnerability Security Profile attached.
Answers
D.
Create a Security Policy rule with vulnerability Security Profile attached.
E.
Enable the "Block sessions with untrusted issuers" setting.
Answers
E.
Enable the "Block sessions with untrusted issuers" setting.
Suggested answer: A, D

Explanation:

You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not decrypt and inspect the session traffic. https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-web-interface-help/ objects/objects-decryption-profile

asked 23/09/2024
Chris Houck
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first