Users on a workstation HP1 access App1 by using the URL https://app1.contoso.com. You need to ensure the intrusion detection and prevention system (IDPS) on FW1 can detect threats in connections from HP1 to Server1. Which two actions should you perform? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable TLS inspection for FW1., Import a server certificate into KV1..
Why this is the answer
To detect threats in encrypted HTTPS traffic, the firewall (FW1) needs to decrypt the traffic. This is achieved by enabling TLS inspection (also known as SSL inspection or HTTPS inspection) on FW1. For TLS inspection to work, FW1 must be able to impersonate the server (Server1) to HP1. This requires importing the server's certificate (or a certificate signed by a trusted CA for the domain) into a secure store accessible by FW1, such as Azure Key Vault (KV1). FW1 then uses this certificate to re-encrypt the traffic after inspection before forwarding it to HP1. Threat intelligence on FW1 would help identify known malicious IPs or domains but wouldn't decrypt traffic for deep packet inspection. Adding an application group to HP1 or a secured virtual network to FW1 are not directly related to decrypting and inspecting HTTPS traffic for IDPS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed