Courseiva

PCNSA Decryption and Monitoring Practice Question

A firewall is configured with decryption and a custom SSL/TLS service profile that has 'Block Expired Certificates' enabled. After renewing a server certificate, some users are unable to access the site. The server certificate is correctly installed. What could be the issue?

⚠ Common exam trap

Many exam-takers assume the client's clock is the culprit (Option B) or that the decryption policy needs updating (Option C), but the firewall's own clock is the critical factor when 'Block Expired Certificates' is enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall's system clock is not synchronized

When 'Block Expired Certificates' is enabled in a custom SSL/TLS service profile, the firewall checks the validity period of the server certificate against its own system clock. If the firewall's clock is not synchronized (e.g., via NTP) and is set to a time outside the new certificate's validity window, the firewall will incorrectly treat the valid renewed certificate as expired and block the connection. This explains why users cannot access the site despite the server certificate being correctly installed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The renewal caused a private key mismatch

    Why it's wrong here

    A private key mismatch would produce a decryption or handshake failure, not a certificate-validity block, and the stem states the certificate is correctly installed. It is tempting because renewal errors often stem from key pairing, but the enabled 'Block Expired Certificates' setting points to a validity-date problem instead.

  • ✗

    The client's system clock is not synchronized

    Why it's wrong here

    The firewall validates the server certificate against its own clock, not the client's, so client clock skew cannot trigger the profile's expired-certificate block. It is tempting because clock drift commonly causes client-side TLS errors, but here the firewall's SSL/TLS service profile is the component rejecting the renewed certificate.

  • ✗

    The decryption policy still points to the old certificate

    Why it's wrong here

    This could be an issue but the scenario states the server certificate is correctly installed, and the firewall may need to import the new cert for inbound inspection; however, the problem is more likely with clock synchronization.

  • ✓

    The firewall's system clock is not synchronized

    Why this is correct

    Expired-certificate blocking compares the certificate's validity window against the firewall's system clock. If NTP is unsynchronised and the clock drifts past the renewed certificate's start or end date, the firewall treats a valid certificate as expired and blocks access.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.