ExamGecko
Question list
Search
Search

Related questions











Question 245 - PCNSE discussion

Report
Export

An engineer configures SSL decryption in order to have more visibility to the internal users' traffic when it is regressing the firewall.

Which three types of interfaces support SSL Forward Proxy? (Choose three.)

A.
High availability (HA)
Answers
A.
High availability (HA)
B.
Layer
Answers
B.
Layer
C.
Virtual Wire
Answers
C.
Virtual Wire
D.
Tap
Answers
D.
Tap
E.
Layer 3
Answers
E.
Layer 3
Suggested answer: B, C, E

Explanation:

SSL Forward Proxy is a feature that allows the firewall to decrypt and inspect outbound SSL traffic from internal users to external servers1. The firewall acts as a proxy (MITM) generating a new certificate for the accessed URL and presenting it to the client during SSL handshake2.

SSL Forward Proxy can be configured on any interface type that supports security policies, which are Layer 2, Virtual Wire, and Layer 3 interfaces1. These interface types allow the firewall to apply security profiles and URL filtering on the decrypted SSL traffic.

asked 23/09/2024
Laura G
57 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first