
Palo Alto NetworksCertified Network Security Analyst
Domain 1Objective 2
1.2 Create and Apply Decryption Profiles NETWORK-SECURITY-ANALYST Practice Questions (Page 1)
Part of the Object Configuration Creation and Application domain, which accounts for 30% of the NETWORK-SECURITY-ANALYST exam.
21questions here
5free pages
8concepts
30%of the exam
Questions 1–5
- 1
Which of the following can be specified as a decryption exclusion in a decryption profile?
Select an answer first - 2
A company is deploying SSL decryption and wants to enforce strong security by only allowing TLS 1.2 and TLS 1.3 for decrypted traffic. However, they have a legacy application that only supports TLS 1.0. The administrator needs to ensure the legacy application continues to work while still enforcing strong security for other traffic. What is the best approach?
Select an answer first - 3
A company is configuring SSL decryption and wants to ensure that only strong cipher suites are used for decrypted traffic. The administrator creates a decryption profile and needs to specify the allowed cipher suites. Where in the decryption profile should this be configured?
Select an answer first - 4
Which of the following is configured within the SSL/TLS Protocol Settings of a decryption profile?
Select an answer first - 5
In a decryption profile, which logging option controls the level of detail recorded for decrypted sessions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ANALYST” is a trademark of its owner, used for identification only.