Courseiva

PCNSA Decryption and Monitoring Practice Question

A security administrator is troubleshooting why SSL decryption is not working for certain websites. The administrator notices that the firewall is generating a certificate signed by the Forward Untrust certificate for these sites. What is the most likely cause?

⚠ Common exam trap

Candidates often confuse the roles of Forward Trust and Forward Untrust certificates, or assuming that certificate pinning is the cause when the Forward Untrust certificate is used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The websites' certificates are not trusted by the firewall's list of trusted CAs.

The Forward Untrust certificate is used when the firewall does not trust the server's certificate. This can happen if the server's certificate is self-signed or issued by a CA not in the firewall's trusted list. The firewall then signs the certificate presented to the client with the Forward Untrust certificate, triggering a warning. Other options would result in different behaviors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The decryption policy is set to 'no-decrypt' for these websites.

    Why it's wrong here

    If the decryption policy is set to 'no-decrypt', the firewall would not decrypt the traffic and would not generate any certificates. The client would connect directly to the server. The presence of a Forward Untrust signed certificate indicates that decryption is attempted but the server's certificate is not trusted.

  • ✓

    The websites' certificates are not trusted by the firewall's list of trusted CAs.

    Why this is correct

    The Forward Untrust certificate is used when the firewall does not trust the server's certificate, such as when the certificate is self-signed or issued by an untrusted CA. The firewall signs the certificate presented to the client with the Forward Untrust certificate, causing a certificate warning in the client's browser. This indicates that the firewall does not trust the site's certificate.

  • ✗

    The Forward Trust certificate is not installed on the firewall.

    Why it's wrong here

    If the Forward Trust certificate is not installed, SSL Forward Proxy decryption cannot function at all. The firewall would not be able to generate certificates for any site. However, the scenario indicates that the firewall is generating certificates signed by the Forward Untrust certificate, which implies that the Forward Trust certificate is present and functioning.

  • ✗

    The websites are using certificate pinning.

    Why it's wrong here

    Certificate pinning would cause the client to reject the firewall-generated certificate, but the firewall would still use the Forward Trust certificate if it trusts the server's certificate. The use of Forward Untrust indicates the firewall does not trust the server's certificate, not that the client is pinning.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.