Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PCNSE Topic 7 Question 72 Discussion

Actual exam question for Palo Alto Networks's PCNSE exam
Question #: 72
Topic #: 7
[All PCNSE Questions]

An engineer is tasked with decrypting web traffic in an environment without an established PKI When using a self-signed certificate generated on the firewall which type of certificate should be in? approved web traffic?

Show Suggested Answer Hide Answer
Suggested Answer: C

The IPv4 Source Interface service route allows the administrator to specify a source interface for a service based on the virtual system. This option overrides the inherited global service route configuration and provides more granular control over the service routes for each virtual system. Reference:

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/virtual-systems/customize-service-routes-for-a-virtual-system.html


Contribute your Thoughts:

Stacey
8 hours ago
But wouldn't using a Public Root CA certificate pose security risks in this scenario?
upvoted 0 times
...
Lorriane
2 days ago
I disagree, I believe the correct answer is C) A Public Root CA certificate.
upvoted 0 times
...
Stacey
9 days ago
I think the answer is A) An Enterprise Root CA certificate.
upvoted 0 times
...
Kimberlie
9 days ago
I think Option B is the correct answer. The self-signed certificate generated on the firewall should be the same as the Forward Trust certificate.
upvoted 0 times
...

Save Cancel