Be able to build and order PAN-OS decryption policies, choose the correct certificate for forward proxy versus inbound inspection, and troubleshoot why traffic is or isn't decrypted. The single most important thing: rule order and the no-decrypt exclusion must match before the decrypt rule.
Start practicing
Decryption and Monitoring — choose a session length
Free · No account required
Domain overview
The Decryption and Monitoring domain covers SSL Forward Proxy and inbound inspection decryption on PAN-OS, plus how decryption policies, certificate management, and decryption exclusions interact with security policy. Questions are scenario-based: you troubleshoot why traffic is or isn't decrypted, pick the right certificate, and order policy rules correctly.
Exam objectives
Configuring SSL Forward Proxy and SSH Proxy decryption policies in PAN-OS
Selecting and installing forward trust, forward untrust, and trusted root CA certificates
Ordering decryption policy rules and using no-decrypt actions for compliance exclusions
Verifying decryption with logs, Decryption Policy counters, and test commands
Assuming a decryption policy alone decrypts traffic, when security policy must also allow the decrypted session and the certificate must be trusted.
Placing the no-decrypt rule for financial or compliance sites below a broader decrypt-all rule, so the exclusion never matches.
Installing the wrong certificate type for inbound inspection, such as a forward trust CA instead of the server certificate or trusted root CA.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?
2An organization deploys SSL Forward Proxy decryption. They want to ensure that traffic to financial websites is not decrypted due to compliance requirements. Which decryption policy configuration should be used?
3A company uses SSL Forward Proxy decryption. The firewall's decryption certificate expires. What immediate impact does this have on traffic?
4Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)
5Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)
6Refer to the exhibit. A user in the trust zone accesses a banking site (category: financial-services). What action will the firewall take on this HTTPS session?
7A university uses a Palo Alto Networks firewall to protect its network. They have implemented SSL Forward Proxy decryption for all student traffic. Recently, the IT helpdesk has received complaints from students that some websites (e.g., online banking, healthcare portals) are not loading properly. The firewall logs show that these sites are being decrypted, and no threats are detected. The university's legal team has advised that decryption of financial and healthcare sites may violate regulations. The network team wants to quickly resolve the issue while ensuring compliance. What is the best course of action?
8A security administrator needs to inspect traffic to a critical web server that uses HTTPS. The firewall is configured as a forward proxy for outbound traffic. Which decryption type should be used to decrypt the traffic inbound to the web server?
9A company wants to decrypt all SSL/TLS traffic from internal users except traffic to financial sites. The firewall is placed as a forward proxy. Which policy configuration ensures that traffic to financial sites is not decrypted?
10A firewall is configured for inbound inspection decryption. Which certificate must be installed on the firewall for this to work?
11A network administrator wants to monitor HTTPS traffic without decrypting it, but still wants to identify the applications being used. Which feature can be used to identify HTTPS applications without decryption?
12A firewall administrator notices that traffic from an internal user is being decrypted, but the user's browser shows a certificate warning. The firewall uses a CA certificate issued by the company's internal PKI. What is the most likely reason for the browser warning?
13A firewall is configured to decrypt SSH traffic. Which type of decryption must be enabled?
14A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?
15A firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which action should be taken?
16Which THREE actions can be performed in a decryption policy? (Choose three.)
17A firewall administrator is configuring SSL decryption for internal users. Which THREE components are required for forward proxy decryption to function properly? (Choose three.)
18A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?
19A security administrator wants to inspect decrypted traffic for threats. What is the minimum set of features required?
20A company has a decryption policy that decrypts all traffic except for traffic to financial sites. However, users report that some financial sites are still being decrypted. What should the admin check first?
21A firewall is configured with decryption and a custom SSL/TLS service profile that has 'Block Expired Certificates' enabled. After renewing a server certificate, some users are unable to access the site. The server certificate is correctly installed. What could be the issue?
22A decryption policy is configured to decrypt traffic to a specific external server. The admin notices that the traffic is not being decrypted. What is the first step in troubleshooting?
23Which THREE factors should be considered when deciding which traffic to decrypt? (Select exactly three.)
24Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)
25Refer to the exhibit. The firewall raises a certificate expiry warning for the decryption CA. Which action is required?
26Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?
27Refer to the exhibit. A firewall log shows a decryption failure for a session. What is the most probable cause?
28A company wants to decrypt all SSL traffic from internal users to external websites. They have deployed a Palo Alto Networks firewall in forward proxy mode and installed a trusted root CA certificate on all endpoints. Users, however, are complaining about certificate errors when accessing HTTPS sites. Which configuration step is most likely missing?
29A network administrator notices that some HTTPS sessions are not being decrypted by the firewall, even though the decryption policy rule is configured to decrypt traffic from a specific subnet. The firewall is in forward proxy mode. All other decryption rules work. What is the most likely cause?
30A security team wants to inspect traffic to and from a critical application server. They configure an inbound decryption rule to decrypt traffic destined to the server's IP address. After deploying, they find that traffic is not being decrypted. What is the first step to troubleshoot?
31A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?
32An organization is using outbound SSL decryption with a forward proxy. They notice that mobile devices (iOS/Android) are having trouble connecting to many HTTPS sites after decryption is enabled. IT has installed the root CA certificate on all devices. What is the most likely reason?
33An administrator is troubleshooting decryption-related connectivity issues. Which two log types should be examined to gather information about decryption actions and errors?
34During SSL decryption, which three factors can cause the firewall to fail to decrypt a session or to bypass decryption?
35A security analyst needs to monitor decryption performance and identify sessions that are bypassing decryption due to policy or technical reasons. Which two monitoring tools or methods can provide this insight?
36A hospital network uses a Palo Alto Networks firewall with outbound SSL decryption. The IT security team notices that during peak hours, the firewall CPU utilization spikes to 95% when decryption is enabled, causing latency for all users. They have already upgraded to maximum licensed throughput and added a dedicated decryption engine. However, the issue persists. The network has 10,000 endpoints and 500 Mbps throughput. The decryption policy includes rules to decrypt all traffic to critical medical cloud services (EHR, PACS) and social media sites. What should the administrator do first to reduce CPU load?
37Refer to the exhibit. An administrator notices a high number of decryption failures. What is the most likely cause?
38Refer to the exhibit. A user reports that they receive a certificate warning when accessing https://example.com. The firewall is configured to decrypt SSL traffic. What is the most likely cause?
39Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?
40A network security administrator needs to confirm whether the firewall is actually decrypting outbound web traffic and which URLs are being decrypted. The administrator wants to see entries that explicitly show the decryption status of each session. Which log type and field combination should the administrator use?
41An administrator must ensure that outbound SSL decryption is applied to user web traffic while excluding banking and healthcare sites that break under inspection. The administrator wants the firewall to skip decryption for these sensitive categories without disabling decryption globally. What should the administrator configure in the decryption policy?
42A network security administrator is configuring a Palo Alto Networks firewall to decrypt outbound HTTPS traffic. The administrator wants to ensure that the firewall can present a valid certificate to internal users for any website they visit, without manually importing each website's certificate. Which configuration is required to achieve this?
43A network security administrator has configured SSL Forward Proxy decryption on a Palo Alto Networks firewall. During routine review, the administrator notices that sessions to banking websites are being decrypted, and users are receiving certificate errors. The administrator wants to stop decrypting these sessions while still decrypting all other HTTPS traffic. Which action should the administrator take?
44A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The administrator wants to exclude employee access to healthcare portals from decryption to comply with privacy regulations, while still decrypting all other HTTPS traffic. Which decryption policy configuration should the administrator use?
45An administrator configures SSL Forward Proxy decryption on a Palo Alto Networks firewall. Internal users report that when they browse to https://portal.hr.example.com, the browser presents a certificate issued by the firewall's forward trust CA instead of the website's real certificate. The administrator wants the browser to trust this dynamically generated certificate without user warnings. What should the administrator do?
46A security administrator is troubleshooting why some SSL Forward Proxy decrypted sessions are failing with 'certificate unknown' errors. The firewall is configured with a self-signed forward trust certificate. Which two actions should the administrator take to resolve the issue? (Choose two.)
47An administrator wants to monitor which applications are being used on the network after SSL decryption. Which Palo Alto Networks feature provides detailed information about applications, including those that use SSL/TLS?
48An administrator has configured SSL decryption for outbound traffic. Users report that they can access most HTTPS sites, but when they visit their bank's website, they receive a certificate error and the connection is blocked. The administrator wants to allow access to the bank site without decryption. What should be configured?
49A security administrator is troubleshooting why SSL decryption is not working for certain websites. The administrator notices that the firewall is generating a certificate signed by the Forward Untrust certificate for these sites. What is the most likely cause?
50A security administrator needs to monitor which applications are being used over encrypted traffic. The firewall is configured to decrypt outbound SSL traffic. Which log type should the administrator review to see the decrypted application details?
51A network security administrator wants to review which users are accessing decrypted HTTPS sites and what URL categories those sites belong to. The administrator needs to see the username, source IP address, destination URL, and the applied decryption policy rule for each session. Which log type should the administrator consult?
52A security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The administrator wants to ensure that the firewall can generate certificates for decrypted sites and that internal users do not receive browser warnings. Which two actions are required to achieve this? (Choose two.)
53A Palo Alto Networks firewall is configured with SSL Forward Proxy decryption for outbound traffic. The administrator notices that some sessions to a banking website are being decrypted even though the organization's policy requires that financial sites be excluded from decryption. The decryption policy rule for financial URL categories is set to 'no-decrypt'. Which action should the administrator take to ensure these sessions are not decrypted?
54An administrator notices that the firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which feature should be used to selectively bypass decryption for certain traffic?
Be able to build and order PAN-OS decryption policies, choose the correct certificate for forward proxy versus inbound inspection, and troubleshoot why traffic is or isn't decrypted. The single most important thing: rule order and the no-decrypt exclusion must match before the decrypt rule.
The Courseiva PCNSA question bank contains 54 questions in the Decryption and Monitoring domain, covering the 10% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Decryption and Monitoring domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included