Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.
Start practicing
Decryption and SSL Inspection — choose a session length
Free · No account required
Domain overview
This domain covers how the firewall decrypts, inspects, and re-encrypts TLS traffic using SSL Forward Proxy, SSL Inbound Inspection, and SSH Proxy, plus how to exempt traffic from decryption. Questions present configuration exhibits, decryption policy rules, and bypassed-session logs, asking you to identify causes and select correct settings.
Exam objectives
Configuring SSL Forward Proxy and SSL Inbound Inspection decryption policies with trusted certificates
Using no-decrypt rules, decryption exclusions, and certificate trust to handle pinned or sensitive traffic
Reading decryption logs and session details to diagnose bypassed, decrypted, or errored sessions
Understanding certificate management, forward trust/forward untrust CAs, and certificate revocation checking
Assuming all HTTPS traffic is decrypted by default; decryption requires explicit decryption policy rules and a forward trust certificate.
Forgetting that no-decrypt rules and exclusions must be ordered correctly, since first-match policy evaluation determines decryption.
Overlooking that pinned applications, certificate errors, or untrusted issuers cause sessions to bypass decryption rather than fail.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?
2A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?
3Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?
4Order the steps to configure a static route on a Palo Alto Networks firewall.
5A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?
6What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?
7During SSL decryption, the firewall logs show 'ssl_decrypt_unsupported_cipher' errors for several connections. What is the likely cause and solution?
8A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?
9Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)
10Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?
11Which TWO of the following are supported decryption scenarios on a Palo Alto Networks firewall?
12A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?
13A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?
14A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?
15A security administrator has configured SSL decryption on a Palo Alto Networks firewall. After decryption, some users report that they cannot access a specific banking website, and the firewall logs show the session as 'decryption excluded' for that site. The administrator wants to ensure that the firewall does not decrypt traffic to this banking site while still decrypting all other HTTPS traffic. What should the administrator configure to achieve this?
16A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?
17A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?
18A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt outbound HTTPS traffic and present a valid certificate to internal users. Which certificate must be installed on the firewall to sign the certificates presented to internal users during SSL Forward Proxy decryption?
19A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?
20A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?
21A network security engineer is troubleshooting an SSL decryption issue. Users report that after decryption was enabled, they cannot access certain HTTPS websites that use certificate pinning. The firewall is configured with SSL Forward Proxy decryption. Which action should the engineer take to allow access to these websites while still decrypting other traffic?
22A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.
The Courseiva PCNSE question bank contains 22 questions in the Decryption and SSL Inspection domain, covering the 7% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Decryption and SSL Inspection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included