Palo Alto Test Questions | Questions with 100% Correct Answers | Verified | Latest Update
Which feature can be configured to block sessions that the firewall cannot decrypt? - Decryption profile in decryption policy What is default setting for "Action" in a decryption policy rule? - No-decrypt Which type of Next Generation Firewall decryption inspects SSL traffic between an internal host and an external web server? - SSL Forward Proxy When SSL encrypted traffic first arrives at the Next Generation Firewall, which technology initially identifies the application as web-browsing? - App-ID On the Next Generation Firewall, which is the first configuration step for SSL Forward Proxy decryption? - Forward Trust Certificate Which type of Next Generation Firewall decryption inspects SSL traffic coming from external users to internal servers? - SSL Inbound Inspection True or False. In the Next Generation Firewall, even if the Decryption policy rule action is "nodecrypt," the Decryption Profile attached to the rule can still be configured to block sessions with expired or untrusted certificates. - True
Document information
- Uploaded on
- February 5, 2023
- Number of pages
- 7
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers