ExamGecko
Question list
Search
Search

Related questions











Question 271 - PCNSE discussion

Report
Export

An engineer is tasked with deploying SSL Forward Proxy decryption for their organization.

What should they review with their leadership before implementation?

A.
Browser-supported cipher documentation
Answers
A.
Browser-supported cipher documentation
B.
Cipher documentation supported by the endpoint operating system
Answers
B.
Cipher documentation supported by the endpoint operating system
C.
URL risk-based category distinctions
Answers
C.
URL risk-based category distinctions
D.
Legal compliance regulations and acceptable usage policies
Answers
D.
Legal compliance regulations and acceptable usage policies
Suggested answer: D

Explanation:

The engineer should review the legal compliance regulations and acceptable usage policies with their leadership before implementing SSL Forward Proxy decryption for their organization. SSL Forward Proxy decryption allows the firewall to decrypt and inspect the traffic from internal users to external servers. This can raise privacy and legal concerns for the users and the organization.

Therefore, the engineer should ensure that the leadership is aware of the implications and benefits of SSL Forward Proxy decryption and that they have a clear policy for informing and obtaining consent from the users. Option A is incorrect because browser-supported cipher documentation is not relevant for SSL Forward Proxy decryption. The firewall uses its own cipher suite to negotiate encryption with the external server, regardless of the browser settings. Option B is incorrect because cipher documentation supported by the endpoint operating system is not relevant for SSL Forward Proxy decryption. The firewall uses its own cipher suite to negotiate encryption with the external server, regardless of the endpoint operating system. Option C is incorrect because URL risk-based category distinctions are not relevant for

SSL Forward Proxy decryption. The firewall can decrypt and inspect traffic based on any URL category, not just risk-based ones.

asked 23/09/2024
sheldan simeina
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first