ExamGecko
Question list
Search
Search

Related questions











Question 259 - PCNSE discussion

Report
Export

An engineer must configure the Decryption Broker feature. To which router must the engineer assign the decryption forwarding interfaces that are used in Decryption Broker security chain?

A.
A virtual router that has no additional interfaces for passing data-type traffic and no other configured routes than those used for the security chain.
Answers
A.
A virtual router that has no additional interfaces for passing data-type traffic and no other configured routes than those used for the security chain.
B.
The default virtual router. If there is no default virtual router , the engineer must create one during setup.
Answers
B.
The default virtual router. If there is no default virtual router , the engineer must create one during setup.
C.
A virtual router that is configured with at least one dynamic routing protocol and has at least one entry in the RIB
Answers
C.
A virtual router that is configured with at least one dynamic routing protocol and has at least one entry in the RIB
D.
The virtual router that routes the traffic that the Decryption Broker security chain inspects.
Answers
D.
The virtual router that routes the traffic that the Decryption Broker security chain inspects.
Suggested answer: D

Explanation:

Decryption Broker is a feature that allows you to use a Palo Alto Networks firewall as a decryption broker for other security devices in your network1. It works by decrypting traffic on one interface and forwarding it to another interface where it can be inspected by other devices before being reencrypted and sent to its destination2. The firewall acts as a transparent bridge between the two interfaces and does not change the source or destination IP addresses of the traffic2.

To configure Decryption Broker, you need to assign decryption forwarding interfaces (DFIs) to the virtual router that routes the traffic that you want to inspect. The DFIs are used to forward decrypted traffic from one interface to another in a security chain3. A security chain is a set of devices that perform different security functions on the same traffic flow3. You can have multiple security chains for different types of traffic or different segments of your network3.

The reason why you need to assign DFIs to the virtual router that routes the traffic is because Decryption Broker uses routing tables to determine which DFI belongs to which security chain and how to forward traffic between them2. If you assign DFIs to a different virtual router than the one that routes the traffic, Decryption Broker will not be able to find them or forward traffic correctly2.

asked 23/09/2024
Nicole Stevens
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first