Courseiva
Decryption and MonitoringeasyMultiple ChoiceObjective-mapped

PCNSA Decryption and Monitoring Practice Question

A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?

⚠ Common exam trap

Palo Alto Networks often tests the distinction between server certificate issues (like self-signed or expired) and the firewall's own certificate trust, leading candidates to incorrectly focus on the server certificate rather than the client's trust of the firewall's CA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall's certificate is not trusted by the client

When forward proxy decryption is used, the firewall generates a new certificate on-the-fly to sign the decrypted traffic. If the firewall's certificate is not trusted by the client (i.e., not installed in the client's trusted root certificate store), the browser will display a certificate warning and block access to the HTTPS site. The default SSL/TLS service profile uses the firewall's own CA certificate, which must be distributed to all clients for seamless decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The decryption policy is set to no-decrypt

    Why it's wrong here

    If set to no-decrypt, the traffic would not be decrypted and would pass through, so access would succeed.

  • The firewall's certificate is not trusted by the client

    Why this is correct

    The firewall presents its own certificate to the client; if the client does not trust the CA that issued the firewall's certificate, the client will show a warning and may block access.

  • The certificate revocation check fails

    Why it's wrong here

    CRL check may cause delay but typically does not block access.

  • The server certificate is self-signed

    Why it's wrong here

    Self-signed certificates are allowed by default in forward proxy.

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.