ExamGecko
Question list
Search
Search

Related questions











Question 80 - PCNSE discussion

Report
Export

During the process of developing a decryption strategy and evaluating which websites are required for corporate users to access, several sites have been identified that cannot be decrypted due to technical reasons. In this case, the technical reason is unsupported ciphers. Traffic to these sites will therefore be blocked if decrypted How should the engineer proceed?

A.
Allow the firewall to block the sites to improve the security posture
Answers
A.
Allow the firewall to block the sites to improve the security posture
B.
Add the sites to the SSL Decryption Exclusion list to exempt them from decryption
Answers
B.
Add the sites to the SSL Decryption Exclusion list to exempt them from decryption
C.
Install the unsupported cipher into the firewall to allow the sites to be decrypted
Answers
C.
Install the unsupported cipher into the firewall to allow the sites to be decrypted
D.
Create a Security policy to allow access to those sites
Answers
D.
Create a Security policy to allow access to those sites
Suggested answer: B

Explanation:

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-exclusions Traffic that breaks decryption for technical reasons, such as using a pinned certificate, an incomplete certificate chain, unsupported ciphers, or mutual authentication (attempting to decrypt the traffic results in blocking the traffic). Palo Alto Networks provides a predefined SSL Decryption Exclusion list (DeviceCertificate ManagementSSL Decryption Exclusion) that excludes hosts with applications and services that are known to break decryption technically from SSL Decryption by default. If you encounter sites that break decryption technically and are not on the SSL Decryption Exclusion list, you can add them to list manually by server hostname. The firewall blocks sites whose applications and services break decryption technically unless you add them to the SSL Decryption Exclusion list.

asked 23/09/2024
Gerhard Seher
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first