ExamGecko
Question list
Search
Search

Related questions











Question 337 - PCNSE discussion

Report
Export

Which three statements accurately describe Decryption Mirror? (Choose three.)

A.
Decryption Mirror requires a tap interface on the firewall
Answers
A.
Decryption Mirror requires a tap interface on the firewall
B.
Use of Decryption Mirror might enable malicious users with administrative access to the firewall to harvest sensitive information that is submitted via an encrypted channel
Answers
B.
Use of Decryption Mirror might enable malicious users with administrative access to the firewall to harvest sensitive information that is submitted via an encrypted channel
C.
Only management consent is required to use the Decryption Mirror feature.
Answers
C.
Only management consent is required to use the Decryption Mirror feature.
D.
Decryption, storage, inspection, and use of SSL traffic are regulated in certain countries.
Answers
D.
Decryption, storage, inspection, and use of SSL traffic are regulated in certain countries.
E.
You should consult with your corporate counsel before activating and using Decryption Mirror in a production environment.
Answers
E.
You should consult with your corporate counsel before activating and using Decryption Mirror in a production environment.
Suggested answer: B, D, E

Explanation:

Decryption Mirror is a feature that allows a Palo Alto Networks firewall to send a copy of decrypted traffic to an external security device or tool for further analysis. The potential risk associated with Decryption Mirror is that if the firewall administrator's credentials are compromised, a malicious user could potentially access sensitive decrypted information. Hence, it's advised to be cautious and ensure proper handling of this feature.

Additionally, laws and regulations regarding the decryption, storage, inspection, and use of SSL/TLS encrypted traffic vary by country and industry. It is crucial to ensure compliance with relevant laws and best practices when using Decryption Mirror. This often requires consultation with corporate legal counsel to understand the implications and ensure that the use of such features does not violate privacy laws or regulatory requirements.

The need for administrative consent and the legal implications of using Decryption Mirror features are outlined in Palo Alto Networks' 'PAN-OS Administrator's Guide' and best practice documentation. It is not specifically required to have a tap interface to use Decryption Mirror, which eliminates option A. Option C is incorrect because it is not just management consent but legal compliance that needs to be considered.

asked 23/09/2024
Martinho Hinterholz
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first