Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NetSec-Analyst Exam - Topic 3 Question 15 Discussion

Based on the image below, what is a risk associated with this configuration?
A) Min Version setting of TLSv1.3 can cause compatibility issues with legacy applications or clients.
B) Authentication algorithm selections can significantly increase resource consumption and cause performance degradation.
C) Encryption algorithms 3DES and RC4 being disabled decreases security posture.
D) Max Version setting of 'Max' enables the use of Perfect Forward Secrecy (PFS) and cannot be decrypted.

Palo Alto Networks NetSec-Analyst Exam - Topic 3 Question 15 Discussion

Actual exam question for Palo Alto Networks's NetSec-Analyst exam
Question #: 15
Topic #: 3
[All NetSec-Analyst Questions]

Based on the image below, what is a risk associated with this configuration?

Show Suggested Answer Hide Answer
Suggested Answer: A

Comprehensive and Detailed 150 to 250 words of Explanation From Palo Alto Networks Network Security Analyst Knowledge:

In the provided image, the Decryption Profile is configured with a Min Version of TLSv1.3. While this represents a high security posture, it introduces a significant operational risk: compatibility issues with legacy applications or clients.

Many older operating systems, web browsers, and legacy internal applications do not support TLS 1.3. If a client or server attempts to negotiate a connection using an older, unsupported protocol version (such as TLS 1.2 or 1.1), the firewall will drop the connection because it falls below the configured minimum threshold. A Network Security Analyst must balance the need for modern encryption with the functional requirements of the network.

Option C is incorrect because disabling weak algorithms like 3DES and RC4 actually improves the security posture. Option D is incorrect because the firewall is fully capable of decrypting traffic using Perfect Forward Secrecy (PFS) if the appropriate certificates are installed. Option B is a general concern for all decryption but is not a specific risk of the versioning shown. Therefore, the most immediate risk of setting the minimum version to TLS 1.3 is the potential disruption of services for any user or system still relying on the widely-used TLS 1.2 protocol or older.


Contribute your Thoughts:

0/2000 characters
Gretchen
1 day ago
Wait, D sounds too good to be true, how can it not be decrypted?
upvoted 0 times
...
Asuncion
7 days ago
C seems off, disabling weak algorithms actually improves security, right?
upvoted 0 times
...
Teri
12 days ago
B is a big deal, performance drops can really hurt user experience.
upvoted 0 times
...
Julio
17 days ago
Totally agree with A, legacy systems can be a pain!
upvoted 0 times
...
Sherell
22 days ago
A) Min Version setting of TLSv1.3 can cause compatibility issues with legacy applications or clients.
upvoted 0 times
...
Thurman
27 days ago
D sounds right because Perfect Forward Secrecy is important, but I’m not clear if "Max" really guarantees it won’t be decrypted.
upvoted 0 times
...
Joseph
1 month ago
I’m a bit confused about C; I thought disabling weak algorithms like 3DES and RC4 actually improves security, not decreases it.
upvoted 0 times
...
Miesha
1 month ago
I think B could be a concern too, especially if the authentication algorithms are resource-intensive. I’ve seen similar questions about performance issues in practice tests.
upvoted 0 times
...
Juan
1 month ago
I remember studying that TLS versions can impact compatibility, so A seems plausible, but I'm not entirely sure if it's the biggest risk.
upvoted 0 times
...

Save Cancel