Courseiva
Decryption and Monitoring →mediumMultiple Select

PCNSA Decryption and Monitoring Practice Question

A security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The administrator wants to ensure that the firewall can generate certificates for decrypted sites and that internal users do not receive browser warnings. Which two actions are required to achieve this? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse the forward trust certificate with the forward untrust certificate, or assuming that firewall-side configuration alone prevents client warnings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the forward trust CA certificate as a trusted root in the internal users' browser or operating system trust stores.

Successful SSL Forward Proxy decryption requires the firewall to have a forward trust certificate and private key to sign re-issued certificates, and clients must trust the forward trust CA to accept those certificates silently. The decryption policy rule and decryption profile are important but do not directly address certificate generation and client trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Install the forward trust CA certificate as a trusted root in the internal users' browser or operating system trust stores.

    Why this is correct

    For clients to accept the re-signed certificates without warnings, the forward trust CA certificate must be trusted by the endpoint. Distributing it via Group Policy, MDM, or manual installation ensures the certificate chain is trusted. Without this step, users see certificate warnings even though decryption is working on the firewall.

  • ✗

    Enable SSL Forward Proxy in a decryption policy rule that matches outbound HTTPS traffic.

    Why it's wrong here

    Enabling SSL Forward Proxy in a decryption policy rule is indeed necessary for the firewall to decrypt matching traffic, but the question asks for the two actions required so the firewall can generate certificates and users avoid warnings. The certificate and client trust steps are the specific requirements for those outcomes. The decryption policy rule is part of the overall configuration but not one of the two listed requirements.

  • ✓

    Generate or import a forward trust certificate and its private key on the firewall.

    Why this is correct

    The forward trust certificate and its private key are used by the firewall to sign the dynamically generated certificates presented to clients during SSL Forward Proxy decryption. Without this certificate, the firewall cannot complete the re-signing process, and decryption cannot proceed. This is a fundamental requirement for forward proxy decryption to function.

  • ✗

    Import the forward untrust certificate into the firewall's trust store for the destination servers.

    Why it's wrong here

    The forward untrust certificate is used by the firewall to sign certificates for sites that fail trust validation or are explicitly untrusted. It does not help the firewall generate certificates for trusted sites, nor does it affect client trust. Importing it into the firewall's trust store is not a standard requirement for forward proxy decryption and would not prevent browser warnings.

  • ✗

    Configure a decryption profile to block sessions with unsupported cipher suites.

    Why it's wrong here

    A decryption profile controls how the firewall handles specific decryption events, such as unsupported ciphers or untrusted certificates, but it is not required for basic forward proxy decryption or client trust. Blocking unsupported cipher suites is an optional hardening measure, not a prerequisite for generating certificates or avoiding browser warnings.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.