PCNSA Decryption and Monitoring Practice Question
A firewall is configured for inbound inspection decryption. Which certificate must be installed on the firewall for this to work?
⚠ Common exam trap
Many candidates confuse inbound inspection decryption with SSL forward proxy decryption, where the firewall uses its own certificate or a CA-signed certificate, leading them to incorrectly choose Option C or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server's certificate and private key.
Inbound inspection decryption requires the firewall to act as a TLS proxy, intercepting and decrypting traffic destined for a protected server. To do this, the firewall must possess the server's certificate and its corresponding private key, allowing it to terminate the TLS connection from the client and re-encrypt traffic to the server. Without the private key, the firewall cannot decrypt the session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The client's certificate.
Why it's wrong here
The client's certificate authenticates the connecting user to the firewall and is irrelevant to decrypting inbound sessions to a server. Client certificates matter for user-ID or mutual TLS enforcement, not for the certificate the firewall presents during inbound inspection.
- ✓
The server's certificate and private key.
Why this is correct
Inbound inspection decryption requires the firewall to present the server's certificate and its private key, enabling it to decrypt and re-encrypt traffic on the server's behalf. Without the matching private key, the firewall cannot complete the TLS handshake.
- ✗
A trusted CA certificate from the enterprise PKI.
Why it's wrong here
A trusted CA certificate from the enterprise PKI lets the firewall issue certificates for internal servers, but inbound inspection requires the firewall to hold the actual server certificate or a subordinate CA able to sign for it; a general trusted root alone does not authorise impersonation.
- ✗
The firewall's own self-signed certificate.
Why it's wrong here
Inbound inspection decrypts traffic destined to internal servers, so the firewall presents the server's certificate or a subordinate CA; its own self-signed certificate is used for management-plane access and outbound forward-proxy trust, not for impersonating internal services.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.