Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Palo Alto Networks logo

Palo Alto NetworksCertified Network Security Architect

Domain 10Objective 8

10.8 Evaluate SSL Inspection Sizing Requirements NETWORK-SECURITY-ARCHITECT Practice Questions (Page 1)

Part of the Private Cloud (PA-Series, VM-Series, Hypervisors) domain, which accounts for 10% of the NETWORK-SECURITY-ARCHITECT exam.

17questions here
4free pages
5concepts
10%of the exam

Questions 1–5

  1. 1foundation · easy

    Which metric is most relevant for sizing the session table when planning SSL inspection?

    Select an answer first
  2. 2expert · hard

    A company is planning to deploy a new firewall for SSL inspection. They have two candidate models: Model A has a high SSL decryption throughput but a low session rate, and Model B has a lower SSL decryption throughput but a high session rate. The company's traffic is a mix of 50% small transactions (e.g., API calls) and 50% large transactions (e.g., file transfers). They expect a 20% annual growth in traffic. Which model should they choose?

    Select an answer first
  3. 3foundation · easy

    Which feature can significantly reduce the CPU overhead of SSL decryption by avoiding repeated full TLS handshakes?

    Select an answer first
  4. 4application · medium

    An organization is sizing a new firewall for SSL inspection. They have analyzed their traffic and found that 70% of their HTTPS traffic is from web browsing with small transactions, and 30% is from file transfers with large transactions. They also expect a 20% annual growth in traffic. Which approach best estimates the SSL inspection sizing requirement?

    Select an answer first
  5. 5foundation · easy

    Which best practice should be applied when sizing SSL inspection to accommodate future growth?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Palo Alto Networks. “NETWORK-SECURITY-ARCHITECT” is a trademark of its owner, used for identification only.