PCNSA Decryption and Monitoring Practice Question
A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?
⚠ Common exam trap
Palo Alto Networks often tests the distinction between server certificate issues (like self-signed or expired) and the firewall's own certificate trust, leading candidates to incorrectly focus on the server certificate rather than the client's trust of the firewall's CA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall's certificate is not trusted by the client
When forward proxy decryption is used, the firewall generates a new certificate on-the-fly to sign the decrypted traffic. If the firewall's certificate is not trusted by the client (i.e., not installed in the client's trusted root certificate store), the browser will display a certificate warning and block access to the HTTPS site. The default SSL/TLS service profile uses the firewall's own CA certificate, which must be distributed to all clients for seamless decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The decryption policy is set to no-decrypt
Why it's wrong here
If set to no-decrypt, the traffic would not be decrypted and would pass through, so access would succeed.
- ✓
The firewall's certificate is not trusted by the client
Why this is correct
The firewall presents its own certificate to the client; if the client does not trust the CA that issued the firewall's certificate, the client will show a warning and may block access.
- ✗
The certificate revocation check fails
Why it's wrong here
CRL check may cause delay but typically does not block access.
- ✗
The server certificate is self-signed
Why it's wrong here
Self-signed certificates are allowed by default in forward proxy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.