Courseiva
Decryption and MonitoringhardMultiple ChoiceObjective-mapped

PCNSA Decryption and Monitoring Practice Question

A mid-sized enterprise has deployed a Palo Alto Networks firewall with SSL Forward Proxy decryption for outbound traffic. The firewall uses a CA-signed certificate from a public CA, and the certificate is installed on all corporate-managed endpoints. Recently, the security team noticed that a few users are unable to access a specific external SaaS application (app.example.com) over HTTPS. Other users can access it without issues. The firewall logs show that for these users, the session is being decrypted and no threat is detected. The application uses a valid certificate from a public CA. The affected users are in the same IP subnet and use the same browser version. Which is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume the decryption policy is misconfigured or that the server certificate is invalid, but the key detail is that the firewall logs show decryption is occurring and no threats are detected, pointing to a client-side trust issue rather than a policy or server problem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall's CA certificate is not installed or trusted on the affected users' endpoints.

SSL Forward Proxy decryption requires the firewall to generate a new certificate on-the-fly for the destination server, signed by the firewall's own CA certificate. If the CA certificate is not trusted on the affected users' endpoints, the browser will display a certificate warning or block the connection entirely, even though the decryption policy is applied and no threats are detected. Since other users in the same subnet can access the application, the issue is isolated to the trust store on the affected machines, not the network or decryption policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The decryption policy is set to 'No Decrypt' for the affected users' source IP range.

    Why it's wrong here

    Logs show decryption is happening, so policy is not bypassing.

  • The firewall is performing SSH proxy instead of SSL decryption for those users.

    Why it's wrong here

    SSH proxy is for SSH traffic, not HTTPS.

  • The firewall's CA certificate is not installed or trusted on the affected users' endpoints.

    Why this is correct

    Without trust, the browser rejects the decrypted connection.

  • The SaaS application's certificate has expired for those users due to time zone differences.

    Why it's wrong here

    The certificate is valid globally; time zone differences do not affect certificate validity.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.