Courseiva
easyMultiple Choice

PCNSA Practice Question: A company has a PA-5250 firewall with 10 Gbps…

A company has a PA-5250 firewall with 10 Gbps threat prevention throughput. They are planning to enable SSL decryption for all traffic. What is the most likely impact on the firewall's throughput?

⚠ Common exam trap

A common mix-up: candidates assume dedicated hardware offloads all encryption overhead, ignoring that SSL decryption requires additional processing for inspection and re-encryption, which reduces overall throughput even with hardware acceleration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Throughput will decrease, typically by 30-50% depending on traffic.

SSL decryption requires the firewall to intercept, decrypt, inspect, and re-encrypt traffic. This process is computationally intensive, especially for high-throughput environments. Even with dedicated hardware, the PA-5250's threat prevention throughput is rated without decryption; enabling it typically reduces throughput by 30-50% due to the overhead of cryptographic operations and deep packet inspection on decrypted content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Throughput will decrease, typically by 30-50% depending on traffic.

    Why this is correct

    SSL decryption forces the PA-5250's dataplane to proxy every TLS session, performing certificate validation, key exchange and re-encryption in software. This processing overhead consumes CPU cycles otherwise used for threat inspection, so the 10 Gbps threat prevention rating drops by roughly 30–50%, satisfying the stem's throughput-impact constraint.

  • ✗

    Throughput will remain the same because the firewall uses dedicated hardware.

    Why it's wrong here

    SSL decryption is performed in software by the firewall's dataplane processors, consuming CPU cycles per session, so throughput drops well below the 10 Gbps threat prevention rating. Dedicated hardware accelerates signature matching and crypto for VPN tunnels, not bulk proxy decryption, which is why that assumption fails here.

  • ✗

    Throughput will increase due to offloading encryption to hardware.

    Why it's wrong here

    Decryption adds processing overhead rather than removing it; the firewall must decrypt, inspect, then re-encrypt each session, so throughput falls. Hardware offload applies to IPsec VPN crypto, where bulk symmetric operations are accelerated, not to proxy-based SSL inspection of arbitrary client traffic.

  • ✗

    Throughput will decrease only if decryption is applied to video traffic.

    Why it's wrong here

    SSL decryption reduces throughput across all decrypted sessions, since the firewall must proxy TLS handshakes and inspect payloads regardless of content type; video traffic is not exempt. It is tempting to assume selective impact, but decryption overhead applies whenever traffic is decrypted.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.