Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A network security team needs to implement decryption for outbound HTTPS traffic to inspect for malware and prevent data exfiltration. However, financial and healthcare website traffic must remain undecrypted due to compliance requirements. Which decryption deployment method should be used?
- ANo Decryption
- BSSL Forward Proxy Decryption
- CSSL Inbound Inspection
- DSSH Proxy Decryption
Show answer & explanationAnswer & explanation
Correct answer: B. SSL Forward Proxy Decryption
SSL Forward Proxy Decryption is used for inspecting outbound encrypted traffic from internal users to external websites. It allows selective decryption policies to be applied, enabling specific categories of traffic (like financial/healthcare) to be excluded from decryption.
Why the other options are wrong
- A. No Decryption would mean the firewall cannot inspect the traffic, failing to meet the malware and data exfiltration requirements.
- C. SSL Inbound Inspection is used for inspecting encrypted traffic coming *to* internal servers from external clients.
- D. SSH Proxy Decryption is for SSH traffic, not HTTPS.
SSL Forward Proxy Decryption
SSL Forward Proxy Decryption on a Palo Alto Networks firewall intercepts and decrypts outbound HTTPS traffic from internal users to external websites, allowing for security inspection and policy enforcement.
- Inspects outbound HTTPS traffic.
- Requires a trusted root CA certificate on client machines.
- Supports selective decryption/exclusion policies.
Memory trick: Forward Proxy is the 'Outbound Traffic Inspector' with an exclusion VIP list.