ExamGecko
Question list
Search
Search

Related questions











Question 284 - PCNSE discussion

Report
Export

Which two factors should be considered when sizing a decryption firewall de-ployment? (Choose two.)

A.
Number of blocked sessions
Answers
A.
Number of blocked sessions
B.
TLS protocol version
Answers
B.
TLS protocol version
C.
Encryption algorithm
Answers
C.
Encryption algorithm
D.
Number of security zones in decryption policies
Answers
D.
Number of security zones in decryption policies
Suggested answer: B, C

Explanation:

According to the Palo Alto Networks documentation1, decryption consumes firewall CPU resources, so it is important to evaluate the amount of SSL decryption that the firewall deployment can support. Two factors that affect the CPU consumption are the TLS protocol version and the encryption algorithm used by the encrypted traffic. The newer versions of TLS (such as TLS 1.3) and the stronger encryption algorithms (such as AES-256-GCM) require more CPU resources to decrypt than the older versions and weaker algorithms. Therefore, the correct answer is B and C.

The other options are not relevant or important for sizing a decryption firewall deployment: Number of blocked sessions: This option refers to the number of sessions that the firewall blocks based on Security policy rules. It does not affect the decryption performance or resource consumption.

Number of security zones in decryption policies: This option refers to the number of security zones that are used to define the source and destination of the traffic to be decrypted. It does not affect the decryption performance or resource consumption.

Reference: 1: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/decryption/prepare-todeploy-decryption/size-the-decryption-firewall-deployment

asked 23/09/2024
Abigail Bormann
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first