ExamGecko
Question list
Search
Search

Related questions











Question 100 - PCNSE discussion

Report
Export

An engineer is configuring SSL Inbound Inspection for public access to a company's application.

Which certificate(s) need to be installed on the firewall to ensure that inspection is performed successfully?

A.
Self-signed CA and End-entity certificate
Answers
A.
Self-signed CA and End-entity certificate
B.
Root CA and Intermediate CA(s)
Answers
B.
Root CA and Intermediate CA(s)
C.
Self-signed certificate with exportable private key
Answers
C.
Self-signed certificate with exportable private key
D.
Intermediate CA (s) and End-entity certificate
Answers
D.
Intermediate CA (s) and End-entity certificate
Suggested answer: D

Explanation:

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/decryption/configure-ssl-inbound- inspection We recommend uploading a certificate chain (a single file) to the firewall if your end- entity (leaf) certificate is signed by one or more intermediate certificates and your web server supports TLS 1.2 and Rivest, Shamir, Adleman (RSA) or Perfect Forward Secrecy (PFS) key exchange algorithms. Uploading the chain avoids client-side server certificate authentication issues.

You should arrange the certificates in the file as follows: End-entity (leaf) certificate Intermediate certificates (in issuing order) (Optional) Root certificate

asked 23/09/2024
Tomislav Bodrozic
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first