ExamGecko
Question list
Search
Search

Related questions











Question 107 - PCNSE discussion

Report
Export

An engineer is planning an SSL decryption implementation

Which of the following statements is a best practice for SSL decryption?

A.
Use the same Forward Trust certificate on all firewalls in the network.
Answers
A.
Use the same Forward Trust certificate on all firewalls in the network.
B.
Obtain a certificate from a publicly trusted root CA for the Forward Trust certificate.
Answers
B.
Obtain a certificate from a publicly trusted root CA for the Forward Trust certificate.
C.
Obtain an enterprise CA-signed certificate for the Forward Trust certificate.
Answers
C.
Obtain an enterprise CA-signed certificate for the Forward Trust certificate.
D.
Use an enterprise CA-signed certificate for the Forward Untrust certificate.
Answers
D.
Use an enterprise CA-signed certificate for the Forward Untrust certificate.
Suggested answer: C

Explanation:

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-forward- proxy(Best Practice) Enterprise CA-signed CertificatesóAn enterprise CA can issue a signing certificate that the firewall can use to sign the certificates for sites which require SSL decryption. When the firewall trusts the CA that signed the certificate of the destination server, the firewall can send a copy of the destination server certificate to the client, signed by the enterprise CA.

This is a best practice because usually all network devices already trust the Enterprise CA (it is usually already installed in the devices' CA Trust storage), so you don't need to deploy the certificate on the endpoints, so therollout process is smoother. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os- admin/decryption/configure-ssl-forward-proxy.html

asked 23/09/2024
Meghan Crofford
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first