Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Analyst

Domain 2Objective 3

2.3 Create and Apply Decryption Policies NETWORK-SECURITY-ANALYST Practice Questions (Page 3)

Part of the Policy Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.

17questions here
4free pages
5concepts
30%of the exam

Questions 11–15

  1. 11expert · hard

    After deploying a decryption policy, an analyst notices that some HTTPS sessions are not being decrypted and the traffic logs show 'Decryption Mismatch' as the action. What does this indicate, and what should the analyst do?

    Select an answer first
  2. 12foundation · easy

    Which setting in a decryption profile controls what happens when the firewall cannot decrypt a session?

    Select an answer first
  3. 13application · medium

    A company wants to decrypt inbound HTTPS traffic to their public-facing web server for threat inspection. They have a valid certificate for the web server. What type of decryption policy should they create?

    Select an answer first
  4. 14application · medium

    A security team is planning to deploy SSL decryption for outbound traffic. They are concerned about legal and compliance issues with inspecting personal traffic. What is the best practice to address this concern?

    Select an answer first
  5. 15foundation · easy

    Which of the following is NOT a typical component of a decryption policy rule?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.