ExamGecko
Question list
Search
Search

Related questions











Question 111 - PCNSE discussion

Report
Export

During the implementation of SSL Forward Proxy decryption, an administrator imports the company's Enterprise Root CA and Intermediate CA certificates onto the firewall. The company's Root and Intermediate CA certificates are also distributed to trusted devices using Group Policy and GlobalProtect. Additional device certificates and/or Subordinate certificates requiring an Enterprise CA chain of trust are signed by the company's Intermediate CA.

Which method should the administrator use when creating Forward Trust and Forward Untrust certificates on the firewall for use with decryption?

A.
Generate a single subordinate CA certificate for both Forward Trust and Forward Untrust.
Answers
A.
Generate a single subordinate CA certificate for both Forward Trust and Forward Untrust.
B.
Generate a CA certificate for Forward Trust and a self-signed CA for Forward Untrust.
Answers
B.
Generate a CA certificate for Forward Trust and a self-signed CA for Forward Untrust.
C.
Generate a single self-signed CA certificate for Forward Trust and another for Forward Untrust
Answers
C.
Generate a single self-signed CA certificate for Forward Trust and another for Forward Untrust
D.
Generate two subordinate CA certificates, one for Forward Trust and one for Forward Untrust.
Answers
D.
Generate two subordinate CA certificates, one for Forward Trust and one for Forward Untrust.
Suggested answer: B

Explanation:

Generate a CA certificate for Forward Trust (step 2) a self-signed CA for Forward Untrust (step 4)https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-forward- proxy

asked 23/09/2024
Carole Pie
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first