Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Analyst

Domain 2Objective 3

2.3 Create and Apply Decryption Policies NETWORK-SECURITY-ANALYST Practice Questions (Page 1)

Part of the Policy Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.

17questions here
4free pages
5concepts
30%of the exam

Questions 1–5

  1. 1application · medium

    A security team wants to ensure that if the firewall cannot decrypt a TLS session due to an unsupported cipher or an expired server certificate, the session is blocked rather than allowed to pass without inspection. What should they configure?

    Select an answer first
  2. 2foundation · easy

    What is the purpose of applying a decryption policy to a security rule?

    Select an answer first
  3. 3foundation · easy

    Which type of decryption policy is used to decrypt inbound traffic destined for internal servers?

    Select an answer first
  4. 4expert · hard

    A firewall has the following decryption policies in order: 1) Decrypt all traffic to '*.example.com', 2) No Decrypt for 'finance.example.com'. A user accesses 'finance.example.com'. The traffic is decrypted. What is the most effective fix?

    Select an answer first
  5. 5application · medium

    A security analyst has deployed a decryption policy and wants to verify that a specific user's HTTPS session was decrypted. Which log should they check and what field should they look for?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.