PCNSA Decryption and Monitoring Practice Question
Exhibit
admin@PA-220> show decryption policy name from to source destination service action type Decrypt-SSH trust untrust 10.0.0.0/24 0.0.0.0/0 any decrypt ssh-proxy admin@PA-220> show session all Total sessions: 1 ID Application State Type Src IP:Port Dst IP:Port Protocol Ingress Egress 1 ssh ACTIVE FLOW 10.0.0.10:22 192.168.1.50:22 tcp eth1/1 eth1/2 admin@PA-220> show system log | match ssh 2024-06-15 12:00:00 ssh_decrypt error Failed to decrypt SSH session: unsupported key exchange algorithm. Src: 10.0.0.10 Dst: 192.168.1.50
Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SSH key exchange algorithm used by the client or server is not in the firewall's supported list.
The error message indicates 'unsupported key exchange algorithm'. SSH decryption requires the firewall to act as a proxy and re-encrypt the session. If the client or server uses a key exchange algorithm that the firewall does not support, decryption will fail. The exhibit shows a policy for SSH decryption and a session, but the algorithm is not supported.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall does not have a certificate installed for SSH decryption.
Why it's wrong here
SSH decryption does not use certificates; the firewall proxies the session and performs its own key exchange, so a missing certificate cannot cause this error. It is tempting because certificate installation is genuinely required for SSL forward proxy decryption, making it the correct fix when TLS, not SSH, decryption fails.
- ✗
The SSH session is using a cipher that is not supported by the firewall's decryption engine.
Why it's wrong here
SSH decryption on Palo Alto firewalls relies on the firewall's own key exchange rather than certificates, and unsupported ciphers are a genuine limitation, but the logged error stems from the decryption profile's configuration, not cipher negotiation alone. It is tempting because cipher mismatch is a real cause of SSH decryption failures in other scenarios.
- ✓
The SSH key exchange algorithm used by the client or server is not in the firewall's supported list.
Why this is correct
SSH decryption requires the firewall to negotiate the session using a supported key exchange algorithm. If the client or server offers only algorithms absent from the firewall's list, the handshake fails and decryption cannot proceed, producing the logged error.
- ✗
The decryption policy is misconfigured because the service is set to 'any' instead of 'ssh'.
Why it's wrong here
Setting the service to 'any' still matches SSH traffic, so it does not by itself break decryption; the error arises from the decryption profile's restrictions on the SSH session. It is tempting because overly broad service definitions are a common policy mistake, and narrowing to 'ssh' is correct practise for precision.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.