Palo Alto Networks Certified Network Security Engineer (PCNSE) — Question 65
An administrator has a requirement to export decrypted traffic from the Palo Alto Networks NGFW to a third-party, deep-level packet inspection appliance.
Which interface type and license feature are necessary to meet the requirement?
Answer options
- A. Decryption Mirror interface with the Threat Analysis license
- B. Virtual Wire interface with the Decryption Port Export license
- C. Tap interface with the Decryption Port Mirror license
- D. Decryption Mirror interface with the associated Decryption Port Mirror license
Correct answer: D
Explanation
The correct answer is D because the Decryption Mirror interface is specifically designed to export decrypted traffic, and the Decryption Port Mirror license enables this functionality. Options A, B, and C do not provide the necessary combination of interface type and licensing to meet the requirement for exporting decrypted traffic.