Courseiva
Securing TraffichardMultiple ChoiceObjective-mapped

PCNSA Securing Traffic Practice Question

An organization has implemented SSL forward proxy decryption. Users on Windows workstations report that many HTTPS sites show certificate errors. The firewall's decryption policy is configured correctly. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall's CA certificate is not installed in the trusted root certificate store on client workstations.

The firewall's CA certificate must be installed in the trusted root certificate store on client workstations; otherwise, the dynamically generated certificates for HTTPS sites will not be trusted, causing certificate errors. Option B is incorrect because the decryption policy does specify a certificate for forward proxy (typically the firewall's own CA certificate), so the issue is not a missing certificate in the policy. Option C is incorrect because the CRL (Certificate Revocation List) is used to check revocation status; not enabling it may allow revoked certificates but does not directly cause certificate trust errors. Option D is incorrect because the server certificate is presented by the web server during the TLS handshake and does not need to be pre-installed on clients; the client validates it against the trusted root store.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The firewall's CA certificate is not installed in the trusted root certificate store on client workstations.

    Why this is correct

    Correct. The firewall's CA certificate must be trusted by clients to avoid certificate errors.

  • The decryption policy does not specify a certificate for forward proxy.

    Why it's wrong here

    Incorrect. The decryption policy does specify a certificate (the CA certificate) for forward proxy; the problem is that clients do not trust that CA certificate.

  • The CRL (Certificate Revocation List) is not enabled on the firewall.

    Why it's wrong here

    Incorrect. CRL is for certificate revocation, not for trust establishment; the issue is about trust in the CA certificate.

  • The server certificate for each HTTPS site is missing from the client's certificate store.

    Why it's wrong here

    Incorrect. The server certificate for HTTPS sites is not needed in the client's store; it's the firewall's CA certificate that must be trusted.

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.