Courseiva
Decryption and MonitoringhardMultiple ChoiceObjective-mapped

PCNSA Decryption and Monitoring Practice Question

During troubleshooting, a firewall shows a large number of SSL decryption failures with error 'certificate_unknown'. The firewall is configured for forward proxy decryption. What is the most likely cause?

⚠ Common exam trap

Palo Alto Networks often tests the distinction between client-side trust issues (option A) and server-side validation failures (option C), leading candidates to incorrectly assume the client must trust the firewall's CA when the error actually stems from the firewall's inability to verify the server certificate's revocation status.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall cannot reach the CRL or OCSP responder to validate the server certificate.

In forward proxy decryption, the firewall must validate the server certificate against a Certificate Revocation List (CRL) or via OCSP to ensure it hasn't been revoked. A 'certificate_unknown' error specifically indicates that the firewall cannot determine the revocation status of the server certificate, often because it cannot reach the CRL distribution point or OCSP responder. This is distinct from a certificate that is simply expired or untrusted by the client.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The client does not trust the firewall's CA certificate.

    Why it's wrong here

    Client trust issues result in browser warnings, not firewall error 'certificate_unknown'.

  • The server certificate is expired.

    Why it's wrong here

    An expired certificate would cause a different error like 'certificate_expired'.

  • The firewall cannot reach the CRL or OCSP responder to validate the server certificate.

    Why this is correct

    This is a common cause of 'certificate_unknown' errors.

  • The decryption policy has an incorrect source zone.

    Why it's wrong here

    Incorrect policy would cause no decryption attempt, not this error.

About these practice questions

One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.