PCNSA Decryption and Monitoring Practice Question
A network administrator notices that some HTTPS sessions are not being decrypted by the firewall, even though the decryption policy rule is configured to decrypt traffic from a specific subnet. The firewall is in forward proxy mode. All other decryption rules work. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often assume the issue is with TLS version support or certificate validation, overlooking the fundamental rule-ordering logic in decryption policy that can cause a no-decrypt rule to preempt a decrypt rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A no-decrypt rule higher in the policy list matches the traffic before the decrypt rule.
In a forward proxy deployment, the firewall evaluates decryption policy rules in order from top to bottom. If a no-decrypt rule is placed higher in the policy list than the decrypt rule for the specific subnet, traffic matching that no-decrypt rule will bypass decryption entirely. This is the most likely cause because all other decryption rules work, indicating the decryption configuration itself is functional, but the order of rule evaluation prevents the intended rule from being applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic is using TLS 1.3 which is not supported by the firewall.
Why it's wrong here
PAN-OS supports TLS 1.3 decryption, so version alone does not prevent decryption. It is tempting because TLS 1.3 encrypts more of the handshake, but the actual cause is typically an exclusion in the decryption policy, an unsupported cipher in the profile, or a pinned or certificate-bound application.
- ✗
The firewall's encryption algorithm settings do not match the server's cipher suite.
Why it's wrong here
Forward proxy decryption terminates the client connection and re-originates the server connection, so the firewall negotiates ciphers independently on each side rather than matching the server's suite. It is tempting because cipher mismatch breaks sessions in other TLS contexts, but here the failure lies in policy matching or profile settings.
- ✗
The SSL/TLS decryption profile has 'Block sessions with expired certificates' enabled.
Why it's wrong here
Blocking expired-certificate sessions affects only flows whose certificates have actually expired, so valid HTTPS sessions from the subnet would still decrypt. That setting is correct when policy requires rejecting expired certificates rather than silently allowing them.
- ✓
A no-decrypt rule higher in the policy list matches the traffic before the decrypt rule.
Why this is correct
A no-decrypt rule positioned above the decrypt rule takes precedence, so matching sessions bypass decryption entirely. Palo Alto firewalls evaluate decryption policy top-down, and the first matching rule wins; the specific subnet's traffic is therefore excluded before the decrypt rule is ever reached.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.