Courseiva

PCNSA · domain

Decryption and Monitoring

The Decryption and Monitoring domain covers SSL Forward Proxy and inbound inspection decryption on PAN-OS, plus how decryption policies, certificate management, and decryption exclusions interact with security policy. Questions are scenario-based: you troubleshoot why traffic is or isn't decrypted, pick the right certificate, and order policy rules correctly.

54 questions12 easy27 medium15 hard

Focused practice

Practice Decryption and Monitoring questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Decryption and Monitoring

Be able to build and order PAN-OS decryption policies, choose the correct certificate for forward proxy versus inbound inspection, and troubleshoot why traffic is or isn't decrypted. The single most important thing: rule order and the no-decrypt exclusion must match before the decrypt rule.

Configuring SSL Forward Proxy and SSH Proxy decryption policies in PAN-OS

Selecting and installing forward trust, forward untrust, and trusted root CA certificates

Ordering decryption policy rules and using no-decrypt actions for compliance exclusions

Verifying decryption with logs, Decryption Policy counters, and test commands

Watch out for

Common Decryption and Monitoring exam traps

  • ▸Assuming a decryption policy alone decrypts traffic, when security policy must also allow the decrypted session and the certificate must be trusted.
  • ▸Placing the no-decrypt rule for financial or compliance sites below a broader decrypt-all rule, so the exclusion never matches.
  • ▸Installing the wrong certificate type for inbound inspection, such as a forward trust CA instead of the server certificate or trusted root CA.

Question index

All Decryption and Monitoring questions (54)

Click any question to see the full explanation, or start a practice session above.

1

A firewall is configured to decrypt SSH traffic. Which type of decryption must be enabled?

Easy
2

A security administrator is troubleshooting why SSL decryption is not working for certain websites. The administrator notices that the firewall is generating a certificate signed by the Forward Untrust certificate for these sites. What is the most likely cause?

Hard
3

A network administrator notices that some HTTPS sessions are not being decrypted by the firewall, even though the decryption policy rule is configured to decrypt traffic from a specific subnet. The firewall is in forward proxy mode. All other decryption rules work. What is the most likely cause?

Medium
4

A Palo Alto Networks firewall is configured with SSL Forward Proxy decryption for outbound traffic. The administrator notices that some sessions to a banking website are being decrypted even though the organization's policy requires that financial sites be excluded from decryption. The decryption policy rule for financial URL categories is set to 'no-decrypt'. Which action should the administrator take to ensure these sessions are not decrypted?

Hard
5

An organization is using outbound SSL decryption with a forward proxy. They notice that mobile devices (iOS/Android) are having trouble connecting to many HTTPS sites after decryption is enabled. IT has installed the root CA certificate on all devices. What is the most likely reason?

Hard
6

A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?

Medium
7

An organization deploys SSL Forward Proxy decryption. They want to ensure that traffic to financial websites is not decrypted due to compliance requirements. Which decryption policy configuration should be used?

Medium
8

An administrator has configured SSL decryption for outbound traffic. Users report that they can access most HTTPS sites, but when they visit their bank's website, they receive a certificate error and the connection is blocked. The administrator wants to allow access to the bank site without decryption. What should be configured?

Medium
9

An administrator must ensure that outbound SSL decryption is applied to user web traffic while excluding banking and healthcare sites that break under inspection. The administrator wants the firewall to skip decryption for these sensitive categories without disabling decryption globally. What should the administrator configure in the decryption policy?

Hard
10

Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?

Medium
11

A university uses a Palo Alto Networks firewall to protect its network. They have implemented SSL Forward Proxy decryption for all student traffic. Recently, the IT helpdesk has received complaints from students that some websites (e.g., online banking, healthcare portals) are not loading properly. The firewall logs show that these sites are being decrypted, and no threats are detected. The university's legal team has advised that decryption of financial and healthcare sites may violate regulations. The network team wants to quickly resolve the issue while ensuring compliance. What is the best course of action?

Medium
12

A security administrator needs to inspect traffic to a critical web server that uses HTTPS. The firewall is configured as a forward proxy for outbound traffic. Which decryption type should be used to decrypt the traffic inbound to the web server?

Easy
13

A firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which action should be taken?

Hard
14

A hospital network uses a Palo Alto Networks firewall with outbound SSL decryption. The IT security team notices that during peak hours, the firewall CPU utilization spikes to 95% when decryption is enabled, causing latency for all users. They have already upgraded to maximum licensed throughput and added a dedicated decryption engine. However, the issue persists. The network has 10,000 endpoints and 500 Mbps throughput. The decryption policy includes rules to decrypt all traffic to critical medical cloud services (EHR, PACS) and social media sites. What should the administrator do first to reduce CPU load?

Medium
15

A company uses SSL Forward Proxy decryption. The firewall's decryption certificate expires. What immediate impact does this have on traffic?

Medium
16

A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?

Medium
17

A security administrator wants to inspect decrypted traffic for threats. What is the minimum set of features required?

Easy
18

A network administrator wants to monitor HTTPS traffic without decrypting it, but still wants to identify the applications being used. Which feature can be used to identify HTTPS applications without decryption?

Medium
19

A decryption policy is configured to decrypt traffic to a specific external server. The admin notices that the traffic is not being decrypted. What is the first step in troubleshooting?

Medium
20

An administrator is troubleshooting decryption-related connectivity issues. Which two log types should be examined to gather information about decryption actions and errors?

Easy
21

A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?

Easy
22

A firewall is configured with decryption and a custom SSL/TLS service profile that has 'Block Expired Certificates' enabled. After renewing a server certificate, some users are unable to access the site. The server certificate is correctly installed. What could be the issue?

Hard
23

A security administrator is troubleshooting why some SSL Forward Proxy decrypted sessions are failing with 'certificate unknown' errors. The firewall is configured with a self-signed forward trust certificate. Which two actions should the administrator take to resolve the issue? (Choose two.)

Hard
24

A network security administrator has configured SSL Forward Proxy decryption on a Palo Alto Networks firewall. During routine review, the administrator notices that sessions to banking websites are being decrypted, and users are receiving certificate errors. The administrator wants to stop decrypting these sessions while still decrypting all other HTTPS traffic. Which action should the administrator take?

Medium
25

A network security administrator wants to review which users are accessing decrypted HTTPS sites and what URL categories those sites belong to. The administrator needs to see the username, source IP address, destination URL, and the applied decryption policy rule for each session. Which log type should the administrator consult?

Easy
26

Refer to the exhibit. A user in the trust zone accesses a banking site (category: financial-services). What action will the firewall take on this HTTPS session?

Medium
27

Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)

Medium
28

Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)

Easy
29

An administrator configures SSL Forward Proxy decryption on a Palo Alto Networks firewall. Internal users report that when they browse to https://portal.hr.example.com, the browser presents a certificate issued by the firewall's forward trust CA instead of the website's real certificate. The administrator wants the browser to trust this dynamically generated certificate without user warnings. What should the administrator do?

Medium
30

A firewall administrator is configuring SSL decryption for internal users. Which THREE components are required for forward proxy decryption to function properly? (Choose three.)

Hard
31

Refer to the exhibit. An administrator notices a high number of decryption failures. What is the most likely cause?

Medium
32

A security team wants to inspect traffic to and from a critical application server. They configure an inbound decryption rule to decrypt traffic destined to the server's IP address. After deploying, they find that traffic is not being decrypted. What is the first step to troubleshoot?

Hard
33

A firewall administrator notices that traffic from an internal user is being decrypted, but the user's browser shows a certificate warning. The firewall uses a CA certificate issued by the company's internal PKI. What is the most likely reason for the browser warning?

Hard
34

A firewall is configured for inbound inspection decryption. Which certificate must be installed on the firewall for this to work?

Easy
35

Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?

Hard
36

A security analyst needs to monitor decryption performance and identify sessions that are bypassing decryption due to policy or technical reasons. Which two monitoring tools or methods can provide this insight?

Hard
37

During SSL decryption, which three factors can cause the firewall to fail to decrypt a session or to bypass decryption?

Medium
38

A company wants to decrypt all SSL/TLS traffic from internal users except traffic to financial sites. The firewall is placed as a forward proxy. Which policy configuration ensures that traffic to financial sites is not decrypted?

Medium
39

Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)

Hard
40

Refer to the exhibit. The firewall raises a certificate expiry warning for the decryption CA. Which action is required?

Easy
41

An administrator wants to monitor which applications are being used on the network after SSL decryption. Which Palo Alto Networks feature provides detailed information about applications, including those that use SSL/TLS?

Easy
42

A company wants to decrypt all SSL traffic from internal users to external websites. They have deployed a Palo Alto Networks firewall in forward proxy mode and installed a trusted root CA certificate on all endpoints. Users, however, are complaining about certificate errors when accessing HTTPS sites. Which configuration step is most likely missing?

Easy
43

A network security administrator needs to confirm whether the firewall is actually decrypting outbound web traffic and which URLs are being decrypted. The administrator wants to see entries that explicitly show the decryption status of each session. Which log type and field combination should the administrator use?

Medium
44

A security administrator needs to monitor which applications are being used over encrypted traffic. The firewall is configured to decrypt outbound SSL traffic. Which log type should the administrator review to see the decrypted application details?

Medium
45

A network security administrator is configuring a Palo Alto Networks firewall to decrypt outbound HTTPS traffic. The administrator wants to ensure that the firewall can present a valid certificate to internal users for any website they visit, without manually importing each website's certificate. Which configuration is required to achieve this?

Medium
46

A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The administrator wants to exclude employee access to healthcare portals from decryption to comply with privacy regulations, while still decrypting all other HTTPS traffic. Which decryption policy configuration should the administrator use?

Medium
47

Refer to the exhibit. A user reports that they receive a certificate warning when accessing https://example.com. The firewall is configured to decrypt SSL traffic. What is the most likely cause?

Hard
48

Which THREE actions can be performed in a decryption policy? (Choose three.)

Medium
49

Which THREE factors should be considered when deciding which traffic to decrypt? (Select exactly three.)

Medium
50

A security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The administrator wants to ensure that the firewall can generate certificates for decrypted sites and that internal users do not receive browser warnings. Which two actions are required to achieve this? (Choose two.)

Medium
51

Refer to the exhibit. A firewall log shows a decryption failure for a session. What is the most probable cause?

Medium
52

An administrator notices that the firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which feature should be used to selectively bypass decryption for certain traffic?

Hard
53

A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?

Easy
54

A company has a decryption policy that decrypts all traffic except for traffic to financial sites. However, users report that some financial sites are still being decrypted. What should the admin check first?

Medium

Frequently asked questions

What does the Decryption and Monitoring domain cover on the PCNSA exam?
Be able to build and order PAN-OS decryption policies, choose the correct certificate for forward proxy versus inbound inspection, and troubleshoot why traffic is or isn't decrypted. The single most important thing: rule order and the no-decrypt exclusion must match before the decrypt rule.
How many questions are in this domain?
This page lists all 54 Decryption and Monitoring questions in the PCNSA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Decryption and Monitoring questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
paloalto-pcnsa PALOALTO-PCNSA decryption monitoring Practice Questions