
Anyone double-checked if "engress outside" (B) is actually first in policy order? Remember from a mock that ordering matters, since firewall applies rules top to bottom. Just want to confirm we're all reading the zones right.
Is the question asking about what gets inspected if SSL decryption is not enabled? That would rule out D, since decrypted traffic only matters if decryption's on. The "allowed" part is key here too-does the rule use allow or deny action?