PCNSA · domain
Decryption and Monitoring
The Decryption and Monitoring domain covers SSL Forward Proxy and inbound inspection decryption on PAN-OS, plus how decryption policies, certificate management, and decryption exclusions interact with security policy. Questions are scenario-based: you troubleshoot why traffic is or isn't decrypted, pick the right certificate, and order policy rules correctly.
Focused practice
Practice Decryption and Monitoring questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Decryption and Monitoring
Be able to build and order PAN-OS decryption policies, choose the correct certificate for forward proxy versus inbound inspection, and troubleshoot why traffic is or isn't decrypted. The single most important thing: rule order and the no-decrypt exclusion must match before the decrypt rule.
Selecting and installing forward trust, forward untrust, and trusted root CA certificates
Ordering decryption policy rules and using no-decrypt actions for compliance exclusions
Verifying decryption with logs, Decryption Policy counters, and test commands
Watch out for
Common Decryption and Monitoring exam traps
- ▸Assuming a decryption policy alone decrypts traffic, when security policy must also allow the decrypted session and the certificate must be trusted.
- ▸Placing the no-decrypt rule for financial or compliance sites below a broader decrypt-all rule, so the exclusion never matches.
- ▸Installing the wrong certificate type for inbound inspection, such as a forward trust CA instead of the server certificate or trusted root CA.
Question index
All Decryption and Monitoring questions (54)
Click any question to see the full explanation, or start a practice session above.
A firewall is configured to decrypt SSH traffic. Which type of decryption must be enabled?
Easy2A security administrator is troubleshooting why SSL decryption is not working for certain websites. The administrator notices that the firewall is generating a certificate signed by the Forward Untrust certificate for these sites. What is the most likely cause?
Hard3A network administrator notices that some HTTPS sessions are not being decrypted by the firewall, even though the decryption policy rule is configured to decrypt traffic from a specific subnet. The firewall is in forward proxy mode. All other decryption rules work. What is the most likely cause?
Medium4A Palo Alto Networks firewall is configured with SSL Forward Proxy decryption for outbound traffic. The administrator notices that some sessions to a banking website are being decrypted even though the organization's policy requires that financial sites be excluded from decryption. The decryption policy rule for financial URL categories is set to 'no-decrypt'. Which action should the administrator take to ensure these sessions are not decrypted?
Hard5An organization is using outbound SSL decryption with a forward proxy. They notice that mobile devices (iOS/Android) are having trouble connecting to many HTTPS sites after decryption is enabled. IT has installed the root CA certificate on all devices. What is the most likely reason?
Hard6A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?
Medium7An organization deploys SSL Forward Proxy decryption. They want to ensure that traffic to financial websites is not decrypted due to compliance requirements. Which decryption policy configuration should be used?
Medium8An administrator has configured SSL decryption for outbound traffic. Users report that they can access most HTTPS sites, but when they visit their bank's website, they receive a certificate error and the connection is blocked. The administrator wants to allow access to the bank site without decryption. What should be configured?
Medium9An administrator must ensure that outbound SSL decryption is applied to user web traffic while excluding banking and healthcare sites that break under inspection. The administrator wants the firewall to skip decryption for these sensitive categories without disabling decryption globally. What should the administrator configure in the decryption policy?
Hard10Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?
Medium11A university uses a Palo Alto Networks firewall to protect its network. They have implemented SSL Forward Proxy decryption for all student traffic. Recently, the IT helpdesk has received complaints from students that some websites (e.g., online banking, healthcare portals) are not loading properly. The firewall logs show that these sites are being decrypted, and no threats are detected. The university's legal team has advised that decryption of financial and healthcare sites may violate regulations. The network team wants to quickly resolve the issue while ensuring compliance. What is the best course of action?
Medium12A security administrator needs to inspect traffic to a critical web server that uses HTTPS. The firewall is configured as a forward proxy for outbound traffic. Which decryption type should be used to decrypt the traffic inbound to the web server?
Easy13A firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which action should be taken?
Hard14A hospital network uses a Palo Alto Networks firewall with outbound SSL decryption. The IT security team notices that during peak hours, the firewall CPU utilization spikes to 95% when decryption is enabled, causing latency for all users. They have already upgraded to maximum licensed throughput and added a dedicated decryption engine. However, the issue persists. The network has 10,000 endpoints and 500 Mbps throughput. The decryption policy includes rules to decrypt all traffic to critical medical cloud services (EHR, PACS) and social media sites. What should the administrator do first to reduce CPU load?
Medium15A company uses SSL Forward Proxy decryption. The firewall's decryption certificate expires. What immediate impact does this have on traffic?
Medium16A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?
Medium17A security administrator wants to inspect decrypted traffic for threats. What is the minimum set of features required?
Easy18A network administrator wants to monitor HTTPS traffic without decrypting it, but still wants to identify the applications being used. Which feature can be used to identify HTTPS applications without decryption?
Medium19A decryption policy is configured to decrypt traffic to a specific external server. The admin notices that the traffic is not being decrypted. What is the first step in troubleshooting?
Medium20An administrator is troubleshooting decryption-related connectivity issues. Which two log types should be examined to gather information about decryption actions and errors?
Easy21A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?
Easy22A firewall is configured with decryption and a custom SSL/TLS service profile that has 'Block Expired Certificates' enabled. After renewing a server certificate, some users are unable to access the site. The server certificate is correctly installed. What could be the issue?
Hard23A security administrator is troubleshooting why some SSL Forward Proxy decrypted sessions are failing with 'certificate unknown' errors. The firewall is configured with a self-signed forward trust certificate. Which two actions should the administrator take to resolve the issue? (Choose two.)
Hard24A network security administrator has configured SSL Forward Proxy decryption on a Palo Alto Networks firewall. During routine review, the administrator notices that sessions to banking websites are being decrypted, and users are receiving certificate errors. The administrator wants to stop decrypting these sessions while still decrypting all other HTTPS traffic. Which action should the administrator take?
Medium25A network security administrator wants to review which users are accessing decrypted HTTPS sites and what URL categories those sites belong to. The administrator needs to see the username, source IP address, destination URL, and the applied decryption policy rule for each session. Which log type should the administrator consult?
Easy26Refer to the exhibit. A user in the trust zone accesses a banking site (category: financial-services). What action will the firewall take on this HTTPS session?
Medium27Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)
Medium28Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)
Easy29An administrator configures SSL Forward Proxy decryption on a Palo Alto Networks firewall. Internal users report that when they browse to https://portal.hr.example.com, the browser presents a certificate issued by the firewall's forward trust CA instead of the website's real certificate. The administrator wants the browser to trust this dynamically generated certificate without user warnings. What should the administrator do?
Medium30A firewall administrator is configuring SSL decryption for internal users. Which THREE components are required for forward proxy decryption to function properly? (Choose three.)
Hard31Refer to the exhibit. An administrator notices a high number of decryption failures. What is the most likely cause?
Medium32A security team wants to inspect traffic to and from a critical application server. They configure an inbound decryption rule to decrypt traffic destined to the server's IP address. After deploying, they find that traffic is not being decrypted. What is the first step to troubleshoot?
Hard33A firewall administrator notices that traffic from an internal user is being decrypted, but the user's browser shows a certificate warning. The firewall uses a CA certificate issued by the company's internal PKI. What is the most likely reason for the browser warning?
Hard34A firewall is configured for inbound inspection decryption. Which certificate must be installed on the firewall for this to work?
Easy35Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?
Hard36A security analyst needs to monitor decryption performance and identify sessions that are bypassing decryption due to policy or technical reasons. Which two monitoring tools or methods can provide this insight?
Hard37During SSL decryption, which three factors can cause the firewall to fail to decrypt a session or to bypass decryption?
Medium38A company wants to decrypt all SSL/TLS traffic from internal users except traffic to financial sites. The firewall is placed as a forward proxy. Which policy configuration ensures that traffic to financial sites is not decrypted?
Medium39Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)
Hard40Refer to the exhibit. The firewall raises a certificate expiry warning for the decryption CA. Which action is required?
Easy41An administrator wants to monitor which applications are being used on the network after SSL decryption. Which Palo Alto Networks feature provides detailed information about applications, including those that use SSL/TLS?
Easy42A company wants to decrypt all SSL traffic from internal users to external websites. They have deployed a Palo Alto Networks firewall in forward proxy mode and installed a trusted root CA certificate on all endpoints. Users, however, are complaining about certificate errors when accessing HTTPS sites. Which configuration step is most likely missing?
Easy43A network security administrator needs to confirm whether the firewall is actually decrypting outbound web traffic and which URLs are being decrypted. The administrator wants to see entries that explicitly show the decryption status of each session. Which log type and field combination should the administrator use?
Medium44A security administrator needs to monitor which applications are being used over encrypted traffic. The firewall is configured to decrypt outbound SSL traffic. Which log type should the administrator review to see the decrypted application details?
Medium45A network security administrator is configuring a Palo Alto Networks firewall to decrypt outbound HTTPS traffic. The administrator wants to ensure that the firewall can present a valid certificate to internal users for any website they visit, without manually importing each website's certificate. Which configuration is required to achieve this?
Medium46A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The administrator wants to exclude employee access to healthcare portals from decryption to comply with privacy regulations, while still decrypting all other HTTPS traffic. Which decryption policy configuration should the administrator use?
Medium47Refer to the exhibit. A user reports that they receive a certificate warning when accessing https://example.com. The firewall is configured to decrypt SSL traffic. What is the most likely cause?
Hard48Which THREE actions can be performed in a decryption policy? (Choose three.)
Medium49Which THREE factors should be considered when deciding which traffic to decrypt? (Select exactly three.)
Medium50A security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The administrator wants to ensure that the firewall can generate certificates for decrypted sites and that internal users do not receive browser warnings. Which two actions are required to achieve this? (Choose two.)
Medium51Refer to the exhibit. A firewall log shows a decryption failure for a session. What is the most probable cause?
Medium52An administrator notices that the firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which feature should be used to selectively bypass decryption for certain traffic?
Hard53A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?
Easy54A company has a decryption policy that decrypts all traffic except for traffic to financial sites. However, users report that some financial sites are still being decrypted. What should the admin check first?
MediumOther domains
All PCNSA exam domains
Frequently asked questions
- What does the Decryption and Monitoring domain cover on the PCNSA exam?
- Be able to build and order PAN-OS decryption policies, choose the correct certificate for forward proxy versus inbound inspection, and troubleshoot why traffic is or isn't decrypted. The single most important thing: rule order and the no-decrypt exclusion must match before the decrypt rule.
- How many questions are in this domain?
- This page lists all 54 Decryption and Monitoring questions in the PCNSA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Decryption and Monitoring questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.