Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NetSec-Analyst Exam - Topic 1 Question 11 Discussion

A company requires that all encrypted traffic from the "Accounting" department be decrypted for inspection, while all other departments remain encrypted. How should the analyst configure the Decryption Policy?
C) Use 'User-ID' in the Decryption Policy to target only members of the Accounting group.
A) Create a single rule with 'Source Zone' set to Accounting and 'Action' to Decrypt.
B) Create a 'No Decrypt' rule for all zones except Accounting.
D) Apply a decryption profile to the Accounting Security Policy rule.

Palo Alto Networks NetSec-Analyst Exam - Topic 1 Question 11 Discussion

Actual exam question for Palo Alto Networks's NetSec-Analyst exam
Question #: 11
Topic #: 1
[All NetSec-Analyst Questions]

A company requires that all encrypted traffic from the "Accounting" department be decrypted for inspection, while all other departments remain encrypted. How should the analyst configure the Decryption Policy?

Show Suggested Answer Hide Answer
Suggested Answer: C

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:

The most granular and efficient way to apply decryption to a specific department is by using User-ID within the Decryption Policy. This ensures that the policy follows the users themselves, regardless of which specific IP address or zone they are currently using.

By selecting the 'Accounting' group from the identity provider (e.g., Active Directory) in the 'Source User' column, the analyst ensures that only their SSL/TLS sessions are decrypted for threat inspection. This objective balances high-security requirements for sensitive departments with the privacy expectations and performance considerations of the rest of the organization. It is a key best practice for a Network Security Analyst to use identity as the primary factor in decryption decisions, as it provides the most persistent and accurate control over the security posture.


Contribute your Thoughts:

0/2000 characters
Angella
2 days ago
C) sounds interesting, but is it really necessary?
upvoted 0 times
...
Galen
7 days ago
I think B) makes more sense for security.
upvoted 0 times
...
Bobbie
12 days ago
A) is the simplest approach.
upvoted 0 times
...
Jerry
17 days ago
I practiced a similar question where applying a decryption profile was key, so D might be the best approach here.
upvoted 0 times
...
Carlene
2 months ago
I feel like option C could be a good choice since using User-ID might help in specifically targeting the Accounting users.
upvoted 0 times
...
Edda
2 months ago
I'm not so sure about A; I remember something about needing to create exceptions for other departments too.
upvoted 0 times
...
Leonora
2 months ago
I think option A sounds right because it directly targets the Accounting department for decryption.
upvoted 0 times
...

Save Cancel