Courseiva

PCNSA Decryption and Monitoring Practice Question

A firewall is configured to decrypt SSH traffic. Which type of decryption must be enabled?

⚠ Common exam trap

Many candidates confuse SSH decryption with SSL decryption and select 'SSL Forward Proxy' because they assume all encrypted traffic is handled by the same mechanism, but SSH uses a completely different protocol and requires a dedicated SSH proxy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH Proxy

SSH traffic uses its own encryption protocol, not SSL/TLS. To decrypt SSH traffic, the firewall must act as a man-in-the-middle using an SSH proxy, which terminates the client's SSH connection and establishes a separate SSH session with the server, allowing inspection of the plaintext content. This is distinct from SSL decryption methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL Forward Proxy

    Why it's wrong here

    SSL Forward Proxy decrypts outbound TLS sessions by presenting a proxy certificate to the client; SSH is not a TLS protocol, so no SSL decryption type can process it. It would be correct for inspecting outbound HTTPS traffic from internal users to external sites.

  • ✗

    Inbound Inspection

    Why it's wrong here

    Inbound Inspection decrypts traffic destined to a protected internal server using that server's certificate and private key; SSH sessions initiated by internal clients to external hosts do not match this direction. It would be correct for inspecting inbound HTTPS connections to a published web server.

  • ✓

    SSH Proxy

    Why this is correct

    SSH Proxy decryption terminates the SSH session at the firewall, decrypting the tunnel so content can be inspected. Standard SSL forward proxy cannot handle SSH, so SSH Proxy is the specific decryption type required for SSH traffic.

  • ✗

    Decryption Mirror

    Why it's wrong here

    Decryption Mirror copies decrypted traffic to a capture interface for analysis; it does not perform the decryption itself and cannot decrypt SSH. It would be correct when feeding decrypted packets to an external monitoring or forensic tool after decryption is already configured elsewhere.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.