Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium
A financial institution requires strict compliance with data privacy regulations, mandating that all outbound encrypted web traffic (HTTPS) from client workstations to external websites must be inspected for threats and sensitive data leakage. The existing network uses a Palo Alto Networks firewall. What decryption policy design element is crucial to implement to meet this requirement without disrupting legitimate business traffic?
- ASSH Decryption
- BSSL Forward Proxy Decryption
- CSSL Inbound Inspection
- DNo Decryption policies
Show answer & explanationAnswer & explanation
Correct answer: B. SSL Forward Proxy Decryption
SSL Forward Proxy Decryption is crucial for inspecting outbound encrypted web traffic (HTTPS) originating from internal clients. It allows the firewall to act as a man-in-the-middle, decrypting, inspecting, and then re-encrypting traffic before it reaches external destinations, thus enabling threat and data leakage prevention.
Why the other options are wrong
- A. SSH Decryption is for Secure Shell traffic, not HTTPS, and is a different feature.
- C. SSL Inbound Inspection is used for decrypting traffic destined for internal servers, not outbound client traffic.
- D. No decryption policies would mean encrypted traffic remains uninspected, failing to meet the compliance requirement.
SSL Forward Proxy Decryption
A decryption method where the firewall intercepts outbound SSL/TLS connections from internal clients, decrypts them for inspection, and then re-encrypts them before forwarding to the external destination. This allows for security policy enforcement on encrypted outbound traffic.
- Inspects outbound client HTTPS traffic
- Firewall acts as man-in-the-middle
- Requires client trust of firewall's certificate
Memory trick: Decryption: Unmasking the hidden threats.