Courseiva

CCNA Decryption Monitoring Questions

54 questions · Decryption Monitoring topic · All types, answers revealed

1
MCQeasy

A firewall is configured to decrypt SSH traffic. Which type of decryption must be enabled?

A.SSL Forward Proxy
B.Inbound Inspection
C.SSH Proxy
D.Decryption Mirror
AnswerC

SSH Proxy decryption terminates the SSH session at the firewall, decrypting the tunnel so content can be inspected. Standard SSL forward proxy cannot handle SSH, so SSH Proxy is the specific decryption type required for SSH traffic.

Why this answer

SSH traffic uses its own encryption protocol, not SSL/TLS. To decrypt SSH traffic, the firewall must act as a man-in-the-middle using an SSH proxy, which terminates the client's SSH connection and establishes a separate SSH session with the server, allowing inspection of the plaintext content. This is distinct from SSL decryption methods.

Exam trap

The trap here is that candidates confuse SSH decryption with SSL decryption and select 'SSL Forward Proxy' because they assume all encrypted traffic is handled by the same mechanism, but SSH uses a completely different protocol and requires a dedicated SSH proxy.

How to eliminate wrong answers

Option A is wrong because SSL Forward Proxy is designed to decrypt SSL/TLS traffic (HTTPS), not SSH traffic, which uses a different encryption protocol and port 22. Option B is wrong because Inbound Inspection is a general traffic inspection policy, not a specific decryption method; it does not inherently decrypt SSH or any encrypted protocol. Option D is wrong because Decryption Mirror is a passive monitoring feature that copies traffic to an external tool for analysis, but it does not perform active decryption of SSH sessions.

2
MCQhard

A security administrator is troubleshooting why SSL decryption is not working for certain websites. The administrator notices that the firewall is generating a certificate signed by the Forward Untrust certificate for these sites. What is the most likely cause?

A.The decryption policy is set to 'no-decrypt' for these websites.
B.The websites' certificates are not trusted by the firewall's list of trusted CAs.
C.The Forward Trust certificate is not installed on the firewall.
D.The websites are using certificate pinning.
AnswerB

The Forward Untrust certificate is used when the firewall does not trust the server's certificate, such as when the certificate is self-signed or issued by an untrusted CA. The firewall signs the certificate presented to the client with the Forward Untrust certificate, causing a certificate warning in the client's browser. This indicates that the firewall does not trust the site's certificate.

Why this answer

The Forward Untrust certificate is used when the firewall does not trust the server's certificate. This can happen if the server's certificate is self-signed or issued by a CA not in the firewall's trusted list. The firewall then signs the certificate presented to the client with the Forward Untrust certificate, triggering a warning.

Other options would result in different behaviors.

Exam trap

The trap here is confusing the roles of Forward Trust and Forward Untrust certificates, or assuming that certificate pinning is the cause when the Forward Untrust certificate is used.

3
MCQmedium

A network administrator notices that some HTTPS sessions are not being decrypted by the firewall, even though the decryption policy rule is configured to decrypt traffic from a specific subnet. The firewall is in forward proxy mode. All other decryption rules work. What is the most likely cause?

A.The traffic is using TLS 1.3 which is not supported by the firewall.
B.The firewall's encryption algorithm settings do not match the server's cipher suite.
C.The SSL/TLS decryption profile has 'Block sessions with expired certificates' enabled.
D.A no-decrypt rule higher in the policy list matches the traffic before the decrypt rule.
AnswerD

A no-decrypt rule positioned above the decrypt rule takes precedence, so matching sessions bypass decryption entirely. Palo Alto firewalls evaluate decryption policy top-down, and the first matching rule wins; the specific subnet's traffic is therefore excluded before the decrypt rule is ever reached.

Why this answer

In a forward proxy deployment, the firewall evaluates decryption policy rules in order from top to bottom. If a no-decrypt rule is placed higher in the policy list than the decrypt rule for the specific subnet, traffic matching that no-decrypt rule will bypass decryption entirely. This is the most likely cause because all other decryption rules work, indicating the decryption configuration itself is functional, but the order of rule evaluation prevents the intended rule from being applied.

Exam trap

The trap here is that candidates often assume the issue is with TLS version support or certificate validation, overlooking the fundamental rule-ordering logic in decryption policy that can cause a no-decrypt rule to preempt a decrypt rule.

How to eliminate wrong answers

Option A is wrong because Palo Alto Networks firewalls support TLS 1.3 decryption in forward proxy mode since PAN-OS 9.0, so TLS 1.3 is not a blocking factor. Option B is wrong because the firewall's encryption algorithm settings in the SSL/TLS decryption profile control which cipher suites the firewall offers to the server; if there is a mismatch, the firewall would typically fall back to a mutually supported cipher rather than skip decryption entirely. Option C is wrong because blocking sessions with expired certificates would cause the session to be terminated or blocked, not silently bypass decryption; the traffic would still be evaluated by the decryption rule.

4
MCQhard

A Palo Alto Networks firewall is configured with SSL Forward Proxy decryption for outbound traffic. The administrator notices that some sessions to a banking website are being decrypted even though the organization's policy requires that financial sites be excluded from decryption. The decryption policy rule for financial URL categories is set to 'no-decrypt'. Which action should the administrator take to ensure these sessions are not decrypted?

A.Configure the forward untrust certificate for the banking site so the firewall does not decrypt it.
B.Disable SSL Forward Proxy globally and rely on SSL Inbound Inspection for outbound traffic.
C.Add the banking website's IP addresses to the SSL Exclude list in the decryption profile.
D.Place the no-decrypt rule above the decrypt rule in the decryption policy rulebase and verify that the URL category is correctly matched.
AnswerD

Decryption policy rules are evaluated top-down, and the first matching rule determines the action. If a decrypt rule appears above the no-decrypt rule, financial sites may be decrypted before the no-decrypt rule is evaluated. Moving the no-decrypt rule to the top and confirming the URL category match ensures financial traffic is excluded as intended.

Why this answer

Decryption policy rules are order-dependent, and the first match wins. If a decrypt rule precedes the no-decrypt rule, financial sites can be decrypted despite the no-decrypt rule's presence. Moving the no-decrypt rule above the decrypt rule and verifying the URL category match ensures financial traffic is correctly excluded from decryption.

Exam trap

The trap here is assuming that adding a no-decrypt rule anywhere in the policy is sufficient, when rule order determines which action takes effect.

5
MCQhard

An organization is using outbound SSL decryption with a forward proxy. They notice that mobile devices (iOS/Android) are having trouble connecting to many HTTPS sites after decryption is enabled. IT has installed the root CA certificate on all devices. What is the most likely reason?

A.The decryption profile does not allow TLS 1.3 connections.
B.The firewall's decryption certificate uses a weak key length.
C.The root CA certificate is not trusted by mobile OS due to certificate transparency or pinning.
D.The firewall is not configured to decrypt traffic from mobile devices.
AnswerC

Certificate pinning and Certificate Transparency enforcement in iOS and Android reject certificates not chaining to a publicly trusted root, regardless of the installed CA. The firewall's re-signed certificates fail these checks, breaking HTTPS connections on mobile devices.

Why this answer

Mobile operating systems (iOS and Android) implement certificate transparency (CT) requirements and certificate pinning for many HTTPS sites. Even if the root CA certificate is installed, the firewall's decryption certificate is not logged in public CT logs, causing the OS to reject the connection. Additionally, pinned certificates (e.g., for Google or Apple services) will fail validation when the firewall presents its own certificate instead of the original server certificate.

Exam trap

The trap here is that candidates assume installing the root CA certificate is sufficient for all devices, overlooking that mobile OSes enforce additional trust mechanisms like certificate transparency and pinning that are not bypassed by a locally installed root CA.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 is fully supported by Palo Alto Networks decryption profiles, and disabling it would affect all clients, not just mobile devices. Option B is wrong because weak key length (e.g., 1024-bit RSA) would cause browser warnings but not outright connection failures on mobile devices; modern mobile OSes accept 2048-bit keys, which are standard. Option D is wrong because the firewall's decryption policy is based on source zones, IP addresses, or user groups, not device type; if mobile devices are in the same zone as other clients, they will be decrypted unless explicitly excluded.

6
MCQmedium

A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?

A.The decryption policy uses 'No Decrypt' for the internal application's URL category.
B.The decryption policy is set to 'Decrypt' for all traffic, causing performance bottlenecks.
C.The firewall's CA certificate is not installed in the trusted root store on user endpoints.
D.The firewall is configured to decrypt traffic from the internal zone, but not the external zone.
AnswerC

SSL Forward Proxy presents a certificate signed by the firewall's CA to endpoints. If that CA certificate is absent from endpoints' trusted root stores, certificate validation fails and internal applications relying on TLS cannot load, matching the reported failures.

Why this answer

SSL Forward Proxy decryption requires the firewall's CA certificate to be trusted by client endpoints. When the firewall generates a new certificate for the internal application's server, the client must trust the firewall's CA to avoid certificate validation errors. Without the CA in the trusted root store, browsers and applications will reject the connection, causing failures for internal applications that rely on SSL/TLS.

Exam trap

Palo Alto Networks often tests the misconception that decryption failures are caused by policy misconfigurations or performance issues, rather than the fundamental requirement of installing the firewall's CA certificate on all client devices.

How to eliminate wrong answers

Option A is wrong because if the decryption policy used 'No Decrypt' for the internal application's URL category, the traffic would bypass decryption entirely and should work normally, not fail. Option B is wrong because while performance bottlenecks can occur with heavy decryption, they would cause slowdowns or timeouts, not outright application failures due to certificate trust issues. Option D is wrong because decryption configuration for internal vs external zones does not directly cause application failures; the issue is the lack of trusted CA on endpoints, not the zone direction.

7
MCQmedium

An organization deploys SSL Forward Proxy decryption. They want to ensure that traffic to financial websites is not decrypted due to compliance requirements. Which decryption policy configuration should be used?

A.Create a decryption rule with action 'Decrypt' and destination zone 'Untrust'.
B.Create a decryption rule with action 'No Decrypt' for the URL category 'Financial Services'.
C.Create a decryption rule with action 'No Decrypt' for all traffic, then a rule above it to decrypt all other traffic.
D.Create a decryption rule with action 'Decrypt' for the URL category 'Financial Services'.
AnswerB

A decryption rule matching the Financial Services URL category with action 'No Decrypt' exempts that traffic from SSL Forward Proxy inspection, satisfying the compliance constraint that financial sites remain encrypted. Rule order matters: it must precede any broader decrypt rule.

Why this answer

SSL Forward Proxy decryption rules are evaluated in order, and the first matching rule determines the action. To exclude financial websites from decryption, you must create a rule with action 'No Decrypt' that matches the 'Financial Services' URL category. This ensures traffic to those sites is not decrypted, meeting compliance requirements.

Exam trap

The trap here is that candidates may think a 'Decrypt' rule with a specific category is needed to handle financial traffic, but the correct approach is to explicitly exclude it with 'No Decrypt' to comply with regulations.

How to eliminate wrong answers

Option A is wrong because a 'Decrypt' action with destination zone 'Untrust' would decrypt all outbound traffic, including financial websites, violating compliance. Option C is wrong because a 'No Decrypt' rule for all traffic would prevent decryption entirely, defeating the purpose of SSL Forward Proxy; the rule order would not allow selective decryption. Option D is wrong because a 'Decrypt' action for 'Financial Services' would explicitly decrypt financial traffic, which is the opposite of the compliance requirement.

8
MCQmedium

An administrator has configured SSL decryption for outbound traffic. Users report that they can access most HTTPS sites, but when they visit their bank's website, they receive a certificate error and the connection is blocked. The administrator wants to allow access to the bank site without decryption. What should be configured?

A.Disable SSL decryption globally and rely on application identification.
B.Add the bank's certificate to the firewall's trusted root CA list.
C.Create a security policy rule that allows the bank's traffic without any decryption profile.
D.A decryption policy rule with action 'no-decrypt' for the bank's URL category.
AnswerD

To exempt specific traffic from decryption, you create a decryption policy rule that matches the desired traffic (e.g., by URL category or FQDN) and set the action to 'no-decrypt'. This allows the traffic to pass through without inspection, preventing certificate errors for sites that may use certificate pinning or have strict security policies. This is the standard method for selective decryption bypass.

Why this answer

To exempt specific traffic from decryption, a decryption policy rule with the action 'no-decrypt' must be created. This rule should match the bank's traffic, often by URL category or FQDN, and be placed above the decrypt rule. This allows the traffic to bypass decryption, preventing certificate errors caused by certificate pinning or other incompatibilities.

Exam trap

The trap here is confusing security policy rules with decryption policy rules; security rules allow or deny traffic but do not control whether decryption occurs.

9
MCQhard

An administrator must ensure that outbound SSL decryption is applied to user web traffic while excluding banking and healthcare sites that break under inspection. The administrator wants the firewall to skip decryption for these sensitive categories without disabling decryption globally. What should the administrator configure in the decryption policy?

A.A decryption policy rule with action 'no-decrypt' and a URL Category match for the sensitive categories
B.A decryption profile with 'Block Untrusted Issuers' enabled for the sensitive categories
C.A security policy rule with action 'allow' and application 'ssl' for the sensitive categories
D.A URL Filtering profile with action 'alert' for the sensitive categories
AnswerA

Decryption policy rules support actions such as decrypt and no-decrypt, and they can match on URL Category. Placing a no-decrypt rule above the general decrypt rule for the sensitive categories ensures those sites bypass inspection while all other web traffic is still decrypted. This meets the requirement without disabling decryption globally and preserves inspection for the remaining traffic.

Why this answer

Decryption policy rules determine which sessions are decrypted or bypassed, and they can match on URL Category. To exclude sensitive categories while decrypting other web traffic, the administrator should create a no-decrypt rule for those categories and place it above the general decrypt rule. Security policy, decryption profiles, and URL filtering profiles do not control whether a session is decrypted, so they cannot satisfy the requirement.

Exam trap

The trap here is confusing decryption policy with security policy or URL filtering, when only a decryption policy no-decrypt rule can exclude traffic from inspection.

10
MCQmedium

Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?

A.The 'strict' profile is misconfigured
B.The Decrypt-Web rule has a profile that blocks decryption
C.The Default-No-Decrypt rule is above Decrypt-Web and matches all traffic
D.The source is set to 'any' in the Decrypt-Web rule
AnswerC

Rule order decides processing: Palo Alto firewalls evaluate decryption rules top-down and stop at the first match. With Default-No-Decrypt positioned above Decrypt-Web, its match-all criteria captures the web server traffic first, so the decrypt rule is never reached and no decryption occurs.

Why this answer

In Palo Alto Networks firewalls, decryption policy rules are evaluated in order from top to bottom, and the first matching rule is applied. If the 'Default-No-Decrypt' rule is placed above the 'Decrypt-Web' rule and matches all traffic (e.g., source/destination 'any'), then all traffic, including traffic to the web server, will match this rule first and will not be decrypted, preventing the 'Decrypt-Web' rule from ever being evaluated.

Exam trap

Palo Alto Networks often tests the concept of rule order in decryption policies, where candidates mistakenly focus on profile settings or source/destination fields instead of recognizing that a higher-priority 'no-decrypt' rule matching all traffic will override any lower-priority decrypt rule.

How to eliminate wrong answers

Option A is wrong because a 'strict' profile is related to SSL/TLS forward proxy settings (e.g., certificate validation, protocol version checks) and does not inherently block decryption; it only enforces security checks on decrypted traffic. Option B is wrong because a decryption profile does not block decryption itself; it controls actions like blocking sessions with expired certificates or unsupported cipher suites, but the rule's action (decrypt vs. no-decrypt) is set in the rule, not the profile. Option D is wrong because setting the source to 'any' in the 'Decrypt-Web' rule would actually broaden its match scope, not prevent decryption; the issue is rule order, not the source field.

11
MCQmedium

A university uses a Palo Alto Networks firewall to protect its network. They have implemented SSL Forward Proxy decryption for all student traffic. Recently, the IT helpdesk has received complaints from students that some websites (e.g., online banking, healthcare portals) are not loading properly. The firewall logs show that these sites are being decrypted, and no threats are detected. The university's legal team has advised that decryption of financial and healthcare sites may violate regulations. The network team wants to quickly resolve the issue while ensuring compliance. What is the best course of action?

A.Modify the existing decrypt rule to decrypt all categories except those two.
B.Disable decryption entirely for all student traffic.
C.Create a security policy rule to allow traffic to those URL categories without inspection.
D.Create a decryption policy rule with action 'No Decrypt' for URL categories 'Financial Services' and 'Health and Medicine', placed above the existing decrypt rule.
AnswerD

SSL Forward Proxy decrypts everything by default, so the compliance breach stems from the decrypt rule itself. A 'No Decrypt' rule for Financial Services and Health and Medicine, positioned above the existing decrypt rule, makes the firewall bypass decryption for those categories, restoring site functionality and satisfying the legal constraint.

Why this answer

It creates a decryption policy rule with action 'No Decrypt' for the specific URL categories 'Financial Services' and 'Health and Medicine', placed above the existing decrypt rule. This ensures that traffic to these sensitive categories is excluded from SSL Forward Proxy decryption, resolving the loading issues caused by certificate pinning or regulatory violations, while still decrypting all other student traffic. The rule order is critical because Palo Alto Networks decryption policies are evaluated top-down, and the first match determines the action.

Exam trap

The trap here is that candidates confuse security policy rules with decryption policy rules, thinking that a security rule can bypass decryption, when in fact decryption is controlled exclusively by decryption policy rules with actions like 'Decrypt' or 'No Decrypt'.

How to eliminate wrong answers

Option A is wrong because modifying the existing decrypt rule to decrypt all categories except those two would require excluding the categories within the same rule, but the correct approach is to use a separate 'No Decrypt' rule above the decrypt rule to ensure proper precedence and avoid unintended decryption of sensitive traffic. Option B is wrong because disabling decryption entirely for all student traffic is an overreaction that would eliminate security visibility for all web traffic, not just the problematic categories, and would not align with the goal of maintaining decryption for other sites. Option C is wrong because creating a security policy rule to allow traffic without inspection does not address the decryption issue; security policies control firewall actions (allow/deny), not decryption decisions, and the traffic would still be decrypted by the existing decrypt rule unless a decryption policy explicitly excludes it.

12
MCQeasy

A security administrator needs to inspect traffic to a critical web server that uses HTTPS. The firewall is configured as a forward proxy for outbound traffic. Which decryption type should be used to decrypt the traffic inbound to the web server?

A.Inbound Inspection Decryption
B.Decryption Mirror
C.Outbound (Forward Proxy) Decryption
D.SSH Proxy
AnswerA

Inbound Inspection decrypts traffic destined to an internal server using that server's certificate and private key, which the firewall holds. Forward proxy handles outbound flows, so it cannot decrypt inbound sessions to the web server; inbound inspection is the matching decryption type.

Why this answer

Inbound Inspection Decryption is used to decrypt traffic destined to a protected server, such as a web server using HTTPS. In this scenario, the firewall acts as a reverse proxy, intercepting inbound connections to the server and decrypting them for inspection before re-encrypting and forwarding the traffic. This allows the security administrator to inspect the payload of HTTPS traffic without requiring client-side configuration.

Exam trap

The trap here is that candidates confuse 'forward proxy' (outbound) with 'reverse proxy' (inbound), leading them to select Outbound (Forward Proxy) Decryption even though the traffic is inbound to the server.

How to eliminate wrong answers

Option B (Decryption Mirror) is wrong because it is not a decryption method; it is a feature that copies traffic to a monitoring tool without decrypting it. Option C (Outbound (Forward Proxy) Decryption) is wrong because it is designed for decrypting traffic initiated by internal clients going to external servers, not inbound traffic to a web server. Option D (SSH Proxy) is wrong because it is used to proxy SSH connections, not to decrypt HTTPS traffic, and it does not apply to inbound web server inspection.

13
MCQhard

A firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which action should be taken?

A.Use decryption mirroring to offload decryption to a dedicated appliance.
B.Change decryption policy to 'no-decrypt' for all traffic.
C.Enable SSL/TLS protocol settings to disable weak ciphers.
D.Create a decryption bypass for traffic to high-bandwidth sites with low security risk.
AnswerD

SSL decryption overloads the firewall's CPU, so bypassing high-bandwidth, low-risk destinations removes that traffic from the decryption engine entirely. This cuts processing load while decryption continues for sensitive flows, satisfying the requirement to reduce utilisation without fully disabling decryption.

Why this answer

Creating a decryption bypass for traffic to high-bandwidth, low-risk sites reduces the CPU load from SSL decryption by exempting that traffic from decryption, while still allowing decryption for higher-risk traffic. This targeted approach maintains security posture without completely disabling decryption, aligning with best practices for managing decryption resources on Palo Alto Networks firewalls.

Exam trap

The trap here is that candidates often confuse decryption mirroring with offloading decryption, not realizing that mirroring only duplicates traffic for analysis and does not reduce the firewall's decryption workload.

How to eliminate wrong answers

Option A is wrong because decryption mirroring sends a copy of decrypted traffic to a monitoring appliance for analysis, but it does not offload the decryption itself; the firewall still performs the CPU-intensive SSL/TLS decryption. Option B is wrong because changing the decryption policy to 'no-decrypt' for all traffic completely disables decryption, which does not meet the requirement to reduce load without completely disabling decryption. Option C is wrong because disabling weak ciphers in SSL/TLS protocol settings improves security by preventing use of insecure algorithms, but it does not reduce CPU utilization from decryption; in fact, it may increase load by forcing negotiation of stronger ciphers that require more processing.

14
MCQmedium

A hospital network uses a Palo Alto Networks firewall with outbound SSL decryption. The IT security team notices that during peak hours, the firewall CPU utilization spikes to 95% when decryption is enabled, causing latency for all users. They have already upgraded to maximum licensed throughput and added a dedicated decryption engine. However, the issue persists. The network has 10,000 endpoints and 500 Mbps throughput. The decryption policy includes rules to decrypt all traffic to critical medical cloud services (EHR, PACS) and social media sites. What should the administrator do first to reduce CPU load?

A.Create a more specific decryption policy to only decrypt necessary traffic.
B.Increase the decryption session timeout value.
C.Replace the firewall with a higher-end model.
D.Enable SSL acceleration hardware offloading.
AnswerA

Decrypting social media traffic consumes disproportionate CPU for negligible security value. Narrowing the policy to essential medical cloud services only reduces the decryption workload, directly addressing the 95% CPU spike that persists despite maximum licensed throughput and a dedicated decryption engine.

Why this answer

The firewall is decrypting unnecessary traffic (social media sites) in addition to critical medical cloud services. By refining the decryption policy to exclude non-essential traffic, the administrator reduces the CPU load from SSL/TLS handshake and encryption processing, directly addressing the spike without requiring hardware changes. This aligns with Palo Alto Networks best practices of minimizing decryption scope to only traffic that requires inspection.

Exam trap

The trap here is that candidates often assume hardware upgrades or offloading features are the immediate fix, but the PCNSA exam emphasizes that policy optimization (decrypting only what is necessary) is the first step before considering hardware changes.

How to eliminate wrong answers

Option B is wrong because increasing the decryption session timeout value does not reduce CPU utilization; it only keeps idle sessions open longer, potentially increasing resource consumption. Option C is wrong because the administrator has already upgraded to maximum licensed throughput and added a dedicated decryption engine, indicating the hardware is not the bottleneck; replacing the firewall would be a costly and unnecessary step without first optimizing the policy. Option D is wrong because SSL acceleration hardware offloading is typically already enabled on Palo Alto Networks firewalls that support it, and the issue persists despite having a dedicated decryption engine, meaning the problem is policy scope, not offloading capability.

15
MCQmedium

A company uses SSL Forward Proxy decryption. The firewall's decryption certificate expires. What immediate impact does this have on traffic?

A.The firewall logs a critical system alert.
B.Users receive certificate warnings when accessing HTTPS sites.
C.Decryption stops working and all SSL traffic is blocked.
D.The firewall automatically renews the certificate from the CA.
AnswerB

SSL Forward Proxy presents the firewall's signing certificate to clients in place of the real server certificate. Once that certificate expires, clients cannot validate the chain, so browsers display certificate warnings and users must manually bypass them before HTTPS pages load.

Why this answer

When the firewall's SSL Forward Proxy decryption certificate expires, the firewall can no longer present a valid certificate to clients during the SSL/TLS handshake. Browsers and applications will detect the expired certificate and display certificate warnings or errors to users, but the firewall may still attempt to decrypt traffic using the expired certificate, causing trust failures. This is the immediate impact because the firewall does not block traffic by default; it continues to proxy the connection, but the client rejects the invalid certificate.

Exam trap

The trap here is that candidates assume decryption stops or traffic is blocked, but Palo Alto Networks firewalls continue to proxy traffic with the expired certificate, causing client-side warnings rather than a firewall-enforced block.

How to eliminate wrong answers

Option A is wrong because a certificate expiration typically generates a system alert or log entry, but the question asks for the immediate impact on traffic, not the logging behavior. Option C is wrong because decryption does not stop; the firewall continues to intercept and re-encrypt traffic using the expired certificate, and SSL traffic is not blocked unless a specific policy action (e.g., 'block if certificate invalid') is configured. Option D is wrong because the firewall does not automatically renew certificates from a CA; certificate renewal is a manual or automated process managed by the administrator, not an automatic firewall function.

16
MCQmedium

A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?

A.Source user
B.URL category
C.Source zone
D.Source IP address
AnswerA

Source user matches decryption policy rules against the username resolved from Active Directory via User-ID, so policies apply per identity rather than by IP address or application. This satisfies the requirement to base decryption on user identity.

Why this answer

Source user is correct because decryption policies based on user identity require matching the user information obtained from Active Directory integration. The firewall uses User-ID to map IP addresses to usernames, and the decryption policy can then enforce rules based on the source user.

Exam trap

PCNSA often tests the confusion between user-based and IP-based policies, especially in decryption contexts where candidates might think source IP is sufficient, but the question explicitly mentions user identity, so source user is the correct match.

How to eliminate wrong answers

URL category is wrong because it matches based on the website category, not user identity. Source zone is wrong because it matches based on the security zone from which traffic originates, not the user. Source IP address is wrong because it matches based on IP address, which does not directly reflect user identity, especially in dynamic environments.

17
MCQeasy

A security administrator wants to inspect decrypted traffic for threats. What is the minimum set of features required?

A.SSL Decryption and Threat Prevention
B.Threat Prevention only
C.SSL Decryption only
D.SSL Decryption and URL Filtering
AnswerA

SSL decryption terminates TLS sessions so the firewall can examine plaintext, which Threat Prevention then matches against signatures and vulnerability profiles. Together they satisfy the stem's requirement to inspect decrypted traffic for threats; neither feature alone provides both decryption and threat detection.

Why this answer

To inspect decrypted traffic for threats, you must first decrypt the traffic using SSL Decryption, which terminates the SSL/TLS session and allows the firewall to examine the plaintext payload. Then, Threat Prevention (which includes IPS, antivirus, and anti-spyware signatures) can analyze that decrypted content for malicious patterns. Without SSL Decryption, Threat Prevention only sees encrypted traffic and cannot inspect the payload; without Threat Prevention, SSL Decryption alone provides no threat detection.

Therefore, both features are required.

Exam trap

The trap here is that candidates often think SSL Decryption alone is sufficient for security, forgetting that decryption is just an enabler and not a security feature itself, or they assume URL Filtering can inspect content, which it cannot.

How to eliminate wrong answers

Option B is wrong because Threat Prevention alone cannot inspect encrypted traffic — it requires decrypted payloads to apply signatures, so it would miss threats in HTTPS sessions. Option C is wrong because SSL Decryption only decrypts traffic but does not perform any threat inspection; it merely makes the content visible but takes no action on threats. Option D is wrong because URL Filtering categorizes and controls access based on URLs, not threat inspection; it does not analyze decrypted content for malware or exploits, so it cannot replace Threat Prevention.

18
MCQmedium

A network administrator wants to monitor HTTPS traffic without decrypting it, but still wants to identify the applications being used. Which feature can be used to identify HTTPS applications without decryption?

A.SSL Decryption Mirror
B.App-ID with SSL protocol detection
C.SSL Forward Proxy
D.URL Filtering
AnswerB

App-ID with SSL protocol detection inspects the TLS handshake fields, such as the server name indication and certificate, to classify the application without decrypting payloads. This satisfies the requirement to identify HTTPS applications while preserving privacy.

Why this answer

App-ID with SSL protocol detection allows the firewall to identify HTTPS applications by inspecting the Server Name Indication (SNI) field in the TLS handshake and the certificate common name, without decrypting the traffic. This enables application identification while preserving encryption, meeting the requirement to monitor HTTPS traffic without decryption.

Exam trap

The trap here is that candidates often confuse SSL Forward Proxy (which requires decryption) with SSL protocol detection (which does not), or assume URL Filtering alone can identify applications within encrypted traffic, but it only identifies the destination URL, not the application itself.

How to eliminate wrong answers

Option A is wrong because SSL Decryption Mirror is not a standard feature; it likely confuses with SSL Forward Proxy decryption or traffic mirroring, which still requires decryption to inspect content. Option C is wrong because SSL Forward Proxy is a decryption method that terminates and re-encrypts HTTPS traffic, requiring decryption to inspect the payload, which violates the 'without decrypting it' requirement. Option D is wrong because URL Filtering relies on URL categories and can identify destinations, but it cannot identify the specific application (e.g., Facebook vs.

YouTube) within HTTPS traffic without decryption or additional metadata.

19
MCQmedium

A decryption policy is configured to decrypt traffic to a specific external server. The admin notices that the traffic is not being decrypted. What is the first step in troubleshooting?

A.Verify that the decryption certificate is valid
B.Disable the SSL/TLS service profile
C.Check the traffic log to see if the policy is matched
D.Ensure that the server's certificate is imported
AnswerC

Before investigating certificates, ciphers or policy ordering, confirm whether the decryption policy is actually being matched. The traffic log shows which policy applied to the session, so verifying the match isolates policy-scope errors from decryption failures.

Why this answer

The first step in troubleshooting a decryption policy that is not decrypting traffic is to check the traffic log to confirm whether the policy is actually being matched. If the traffic does not match the decryption rule, no decryption will occur regardless of certificate validity or other settings. This aligns with the systematic troubleshooting approach of verifying policy application before investigating deeper configuration issues.

Exam trap

The trap here is that candidates often jump to certificate issues (A or D) because SSL/TLS decryption heavily involves certificates, but the most fundamental check is whether the policy is even being triggered — a classic 'policy before crypto' troubleshooting principle.

How to eliminate wrong answers

Option A is wrong because verifying the decryption certificate is a secondary step; if the policy is not matched, the certificate is never used. Option B is wrong because disabling the SSL/TLS service profile would break decryption entirely, not help diagnose why an existing policy is not being applied. Option D is wrong because importing the server's certificate is not required for outbound decryption (forward proxy) — the firewall generates its own certificate for the client, and the server's certificate is validated but not imported.

20
Multi-Selecteasy

An administrator is troubleshooting decryption-related connectivity issues. Which two log types should be examined to gather information about decryption actions and errors?

Select 2 answers
A.System logs
B.URL Filtering logs
C.Decryption logs
D.Threat logs
E.Traffic logs
AnswersC, E

Decryption logs offer detailed information such as decryption reason, cipher, and certificate details.

Why this answer

Decryption logs are specifically designed to record details about SSL/TLS decryption actions, including handshake failures, certificate validation errors, and decryption policy matches. When troubleshooting connectivity issues related to decryption, these logs provide the most direct insight into why a session might be blocked or failing due to decryption errors.

Exam trap

Palo Alto Networks often tests the distinction between Traffic logs (which show the result of decryption, such as a deny action) and Decryption logs (which show the decryption process itself), leading candidates to mistakenly choose Traffic logs as the primary source for decryption errors.

21
MCQeasy

A company uses forward proxy decryption. A user cannot access an HTTPS site. The decryption policy is configured with the default SSL/TLS service profile. What is the most likely issue?

A.The decryption policy is set to no-decrypt
B.The firewall's certificate is not trusted by the client
C.The certificate revocation check fails
D.The server certificate is self-signed
AnswerB

The firewall presents its own certificate to the client; if the client does not trust the CA that issued the firewall's certificate, the client will show a warning and may block access.

Why this answer

When forward proxy decryption is used, the firewall generates a new certificate on-the-fly to sign the decrypted traffic. If the firewall's certificate is not trusted by the client (i.e., not installed in the client's trusted root certificate store), the browser will display a certificate warning and block access to the HTTPS site. The default SSL/TLS service profile uses the firewall's own CA certificate, which must be distributed to all clients for seamless decryption.

Exam trap

Palo Alto Networks often tests the distinction between server certificate issues (like self-signed or expired) and the firewall's own certificate trust, leading candidates to incorrectly focus on the server certificate rather than the client's trust of the firewall's CA.

How to eliminate wrong answers

Option A is wrong because if the decryption policy were set to no-decrypt, the firewall would simply pass the traffic without inspection, and the user would be able to access the HTTPS site normally (assuming no other blocks). Option C is wrong because a certificate revocation check failure would typically result in a warning or block only if the firewall is configured to enforce revocation, but the question states the decryption policy uses the default SSL/TLS service profile, which does not enable revocation checking by default. Option D is wrong because a self-signed server certificate would cause a warning in the client's browser regardless of decryption, but the question specifically describes a scenario where forward proxy decryption is enabled, and the issue is that the firewall's own certificate is not trusted by the client, not the server's certificate.

22
MCQhard

A firewall is configured with decryption and a custom SSL/TLS service profile that has 'Block Expired Certificates' enabled. After renewing a server certificate, some users are unable to access the site. The server certificate is correctly installed. What could be the issue?

A.The renewal caused a private key mismatch
B.The client's system clock is not synchronized
C.The decryption policy still points to the old certificate
D.The firewall's system clock is not synchronized
AnswerD

Expired-certificate blocking compares the certificate's validity window against the firewall's system clock. If NTP is unsynchronised and the clock drifts past the renewed certificate's start or end date, the firewall treats a valid certificate as expired and blocks access.

Why this answer

When 'Block Expired Certificates' is enabled in a custom SSL/TLS service profile, the firewall checks the validity period of the server certificate against its own system clock. If the firewall's clock is not synchronized (e.g., via NTP) and is set to a time outside the new certificate's validity window, the firewall will incorrectly treat the valid renewed certificate as expired and block the connection. This explains why users cannot access the site despite the server certificate being correctly installed.

Exam trap

The trap here is that candidates often assume the client's clock is the culprit (Option B) or that the decryption policy needs updating (Option C), but the firewall's own clock is the critical factor when 'Block Expired Certificates' is enabled.

How to eliminate wrong answers

Option A is wrong because a private key mismatch would cause the SSL/TLS handshake to fail with a different error (e.g., 'decryption failed' or 'certificate unknown'), not a block specifically tied to certificate expiry. Option B is wrong because the client's system clock is irrelevant to the firewall's 'Block Expired Certificates' check; the firewall evaluates the certificate against its own clock, not the client's. Option C is wrong because the decryption policy references the service profile (which contains the 'Block Expired Certificates' setting), not the server certificate itself; the renewed certificate is correctly installed on the server, so the policy does not 'point' to an old certificate.

23
Multi-Selecthard

A security administrator is troubleshooting why some SSL Forward Proxy decrypted sessions are failing with 'certificate unknown' errors. The firewall is configured with a self-signed forward trust certificate. Which two actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Change the decryption rule action to 'no-decrypt' for affected sites.
B.Install the forward trust certificate's root CA on all client systems.
C.Configure a decryption profile to allow expired certificates.
D.Import a CA certificate signed by a trusted public CA as the forward trust certificate.
E.Enable SSL decryption on the untrust zone.
AnswersB, D

If the forward trust certificate is self-signed, its root CA must be distributed to and trusted by all clients. Without this, clients will not trust the certificates generated by the firewall for decrypted sites, causing 'certificate unknown' errors. This is a common requirement for SSL Forward Proxy decryption.

Why this answer

The 'certificate unknown' error occurs because clients do not trust the forward trust certificate used by the firewall to re-sign decrypted traffic. To fix this, the forward trust certificate must be either signed by a trusted CA or its root CA must be installed on clients. These two actions ensure that clients trust the certificates generated by the firewall, allowing decryption to proceed without errors.

Exam trap

The trap here is assuming that enabling decryption on the untrust zone or adjusting decryption profiles will solve certificate trust errors, when the root cause is client-side trust of the forward trust certificate.

24
MCQmedium

A network security administrator has configured SSL Forward Proxy decryption on a Palo Alto Networks firewall. During routine review, the administrator notices that sessions to banking websites are being decrypted, and users are receiving certificate errors. The administrator wants to stop decrypting these sessions while still decrypting all other HTTPS traffic. Which action should the administrator take?

A.Create a no-decrypt policy rule for the banking sites and place it above the decrypt rule.
B.Add the banking sites to the SSL Decryption Exclusion list in the decryption profile.
C.Change the decryption rule action from 'decrypt' to 'no-decrypt' for all traffic, then create a new rule to decrypt everything except banking.
D.Modify the decryption profile to disable decryption for the banking sites.
AnswerA

In SSL Forward Proxy, decryption policy is evaluated top-down. A no-decrypt rule matched before the decrypt rule exempts specific destinations from decryption while allowing all other HTTPS traffic to be decrypted by the subsequent decrypt rule. This is the correct way to selectively exclude traffic without disabling decryption globally.

Why this answer

Decryption policy rules are evaluated in order, and a no-decrypt rule placed above a decrypt rule will match banking traffic first, preventing decryption. The decrypt rule below continues to decrypt all other HTTPS traffic. This approach is granular, efficient, and maintains security visibility for the majority of traffic while respecting privacy or compliance requirements for financial sites.

Exam trap

The trap here is assuming that decryption exclusions are configured in the decryption profile or exclusion list, when they are actually controlled by policy rule order.

25
MCQeasy

A network security administrator wants to review which users are accessing decrypted HTTPS sites and what URL categories those sites belong to. The administrator needs to see the username, source IP address, destination URL, and the applied decryption policy rule for each session. Which log type should the administrator consult?

A.Decryption log
B.Configuration log
C.Threat log
D.Traffic log
AnswerD

The Traffic log records sessions passing through the firewall, including source user, source and destination IP addresses, destination URL when available, application, and the security policy rule that allowed or denied the session. For decrypted HTTPS traffic, the URL and decryption policy information are visible in the Traffic log, making it the appropriate place to review user access to decrypted sites.

Why this answer

The Traffic log is the primary session log on Palo Alto Networks firewalls and includes user identification, URLs, applications, and policy rule matches. For decrypted HTTPS sessions, it shows the URL and the decryption policy rule, enabling administrators to review user access to decrypted sites. Other log types serve different purposes and do not provide this combined session view.

Exam trap

The trap here is assuming a dedicated Decryption log exists, when decryption details are actually recorded within the Traffic log.

26
MCQmedium

Refer to the exhibit. A user in the trust zone accesses a banking site (category: financial-services). What action will the firewall take on this HTTPS session?

A.Error due to rule conflict
B.Block
C.No Decrypt (bypass decryption)
D.Decrypt
AnswerC

No Decrypt satisfies the financial-services category constraint: the firewall matches the URL category and applies a decryption bypass policy, so the HTTPS session passes through encrypted. Traffic still undergoes App-ID and security profile inspection, but the firewall cannot inspect payload contents, preserving privacy for banking sessions.

Why this answer

The firewall is configured with a decryption policy that matches the banking site (financial-services category) and has the action set to 'No Decrypt'. This action explicitly bypasses SSL/TLS decryption for the session, allowing the HTTPS traffic to pass through without inspection. The user in the trust zone accessing the site will therefore have the session proceed without decryption.

Exam trap

The trap here is that candidates often assume any HTTPS session must be decrypted for inspection, but the 'No Decrypt' action explicitly bypasses decryption while still allowing the session through, which is a common configuration for regulated or sensitive traffic categories.

How to eliminate wrong answers

Option A is wrong because there is no rule conflict; the decryption policy explicitly defines a 'No Decrypt' action for the financial-services category, which is a valid and unambiguous configuration. Option B is wrong because the decryption policy does not block the session; 'No Decrypt' allows the traffic to pass without decryption, whereas a block would require a security rule with a deny action. Option D is wrong because the decryption policy action is 'No Decrypt', not 'Decrypt'; the firewall will not perform SSL/TLS decryption on this session.

27
Multi-Selectmedium

Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)

Select 3 answers
A.No Decrypt
B.Forward Untrust Certificate
C.Block
D.Forward
E.Decrypt
AnswersA, B, E

No Decrypt leaves matching traffic encrypted, so the firewall forwards it without inspection. This satisfies the scenario's requirement to exempt traffic that cannot legally be decrypted, such as financial or healthcare sessions, while still enforcing the decryption policy rule's action set alongside Decrypt and No Decrypt with decryption profile options.

Why this answer

In a Palo Alto Networks decryption policy, the three valid rule actions are No Decrypt, Forward Untrust Certificate, and Decrypt. Option A (No Decrypt) is correct because it allows specified traffic to bypass decryption entirely, which is used for traffic that cannot or should not be decrypted, such as pinned or sensitive sessions. Option B (Forward Untrust Certificate) is correct because it is a specific decryption action that presents the firewall's untrust certificate to clients when the destination server certificate is not trusted, enabling continued inspection.

Option E (Decrypt) is correct because it is the primary action that instructs the firewall to decrypt and inspect matching SSL/TLS traffic. Options C (Block) and D (Forward) are not valid decryption policy actions; Block is a security policy action, and Forward is not a decryption rule action in this context.

Exam trap

Palo Alto Networks often tests the distinction between decryption policy actions and security policy actions, so the trap here is confusing 'Block' (a security rule action) with decryption rule actions, or assuming 'Forward' is a decryption action when it is actually a default behavior for non-decrypted traffic.

28
Multi-Selecteasy

Which TWO logs are most useful for troubleshooting SSL decryption issues? (Select exactly two.)

Select 2 answers
A.GlobalProtect log
B.System log
C.Threat log
D.Traffic log
E.URL Filtering log
AnswersB, D

The system log records decryption engine state changes, including SSL forward proxy failures, certificate validation errors, and resource exhaustion events. It satisfies the stem's troubleshooting constraint by exposing why the firewall cannot decrypt traffic, such as unsupported ciphers or untrusted issuer chains, rather than merely listing decrypted sessions.

Why this answer

The System log (B) records decryption-related events, such as certificate validation failures, handshake errors, and unsupported cipher suites, which are critical for diagnosing SSL decryption issues. The Traffic log (D) shows whether traffic was decrypted or bypassed, including the 'Decrypted' flag and details about the SSL/TLS handshake, allowing you to verify decryption policy application.

Exam trap

The trap here is that candidates often confuse the Threat log (which shows post-decryption threats) with logs that diagnose the decryption process itself, or mistakenly think GlobalProtect logs are relevant because SSL decryption is sometimes used in VPN environments.

29
MCQmedium

An administrator configures SSL Forward Proxy decryption on a Palo Alto Networks firewall. Internal users report that when they browse to https://portal.hr.example.com, the browser presents a certificate issued by the firewall's forward trust CA instead of the website's real certificate. The administrator wants the browser to trust this dynamically generated certificate without user warnings. What should the administrator do?

A.Configure the decryption policy to use the forward untrust certificate for the affected destination and add the site to the SSL Exclude list.
B.Enable SSL Forward Proxy only for the specific URL category and disable certificate pinning on the firewall.
C.Import the forward trust certificate and its private key into the firewall and enable SSL Forward Proxy in the decryption policy.
D.Install the forward trust CA certificate into the internal users' browser or operating system trust stores as a trusted root.
AnswerD

When SSL Forward Proxy re-signs a server certificate, the new certificate is signed by the firewall's forward trust CA. For browsers to accept it silently, that CA certificate must be installed as a trusted root in the client trust store. Distributing the forward trust CA certificate through Group Policy, MDM, or a similar mechanism removes the warning.

Why this answer

SSL Forward Proxy generates a substitute certificate for each decrypted server, signed by the firewall's forward trust CA. Clients will only accept that certificate without warnings if the forward trust CA certificate is present in their trust store. The firewall-side configuration is already correct; the missing piece is client-side trust distribution.

Exam trap

The trap here is assuming that importing the forward trust certificate into the firewall is enough, when the certificate must also be trusted by the client endpoints.

30
Multi-Selecthard

A firewall administrator is configuring SSL decryption for internal users. Which THREE components are required for forward proxy decryption to function properly? (Choose three.)

Select 3 answers
A.The server's private key
B.The firewall's root CA certificate deployed to client browsers
C.A security policy rule allowing decrypted traffic
D.A decryption policy rule with action 'decrypt'
E.A CA certificate installed on the firewall
AnswersB, D, E

Forward proxy decryption requires the firewall to re-sign server certificates with its own CA. Deploying that root CA certificate to client browsers lets them trust the re-signed certificates, preventing browser trust errors for every decrypted session.

Why this answer

Option B is correct because forward proxy SSL decryption requires the firewall to act as a man-in-the-middle, which means clients must trust the firewall's root CA certificate; deploying it to client browsers allows them to validate the re-signed certificates without errors. Option D is correct because a decryption policy rule with action 'decrypt' is what actually instructs the firewall to intercept and decrypt matching sessions; without it, traffic is not decrypted. Option E is correct because the firewall needs a CA certificate installed on itself to sign the forged certificates it presents to clients during decryption.

Option A is not required because the server's private key is never needed for forward proxy decryption; the firewall generates its own certificates signed by its CA. Option C is not a required component for decryption to function, since decryption is governed by the decryption policy, not a security policy rule allowing decrypted traffic.

Exam trap

The trap here is confusing forward proxy decryption (which requires the firewall's own CA certificate and its deployment to clients) with inbound/SSL termination decryption (which requires the server's private key), leading candidates to incorrectly select Option A.

31
MCQmedium

Refer to the exhibit. An administrator notices a high number of decryption failures. What is the most likely cause?

A.The SSL session cache size is too small.
B.The firewall's certificate is not trusted by client devices.
C.SSL Forward Proxy is not enabled.
D.Non-HTTP traffic is being decrypted.
AnswerB

Decryption failures occur when clients reject the firewall's forward-trust certificate during SSL forward proxy, because the certificate authority is not in their trust store. The firewall's own certificate being untrusted by client devices directly explains the failures shown in the exhibit.

Why this answer

When the firewall's certificate is not trusted by client devices, clients will reject the SSL handshake, resulting in decryption failures. This is a common issue in SSL Forward Proxy deployments where the firewall generates a certificate for each session, and clients must trust the firewall's CA certificate. Without this trust, clients display certificate warnings or fail to connect, leading to a high number of decryption failures.

Exam trap

Palo Alto Networks often tests the distinction between decryption failures caused by untrusted certificates versus configuration issues like cache size or protocol mismatches, trapping candidates who confuse performance problems with trust-related handshake failures.

How to eliminate wrong answers

Option A is wrong because the SSL session cache size affects performance and renegotiation overhead, not the number of decryption failures; a small cache would cause more full handshakes but not failures. Option C is wrong because SSL Forward Proxy must be enabled for decryption to occur; if it were not enabled, there would be no decryption at all, not a high number of failures. Option D is wrong because non-HTTP traffic being decrypted would cause errors or performance issues, but the firewall typically only attempts decryption on allowed ports (e.g., 443), and this would not be the primary cause of a high failure count.

32
MCQhard

A security team wants to inspect traffic to and from a critical application server. They configure an inbound decryption rule to decrypt traffic destined to the server's IP address. After deploying, they find that traffic is not being decrypted. What is the first step to troubleshoot?

A.Confirm that the decryption profile is set to 'decrypt' and that the forward proxy option is enabled.
B.Check the decryption policy rule order and ensure it is before any no-decrypt rules.
C.Verify that the server's certificate is installed on the firewall.
D.Ensure that the firewall has a valid certificate for inbound inspection.
AnswerB

Decryption policies evaluate top-down, so an earlier no-decrypt rule matching the server's IP silently bypasses the inbound decryption rule. Verifying rule order confirms the decrypt rule precedes any no-decrypt entry covering that traffic, satisfying the stem's requirement that traffic to the critical application server actually be decrypted.

Why this answer

In Palo Alto Networks firewalls, decryption policy rules are evaluated in order from top to bottom, and the first matching rule is applied. If a 'no-decrypt' rule appears before the inbound decryption rule, traffic matching the server's IP will be handled by the no-decrypt rule and will not be decrypted. Therefore, verifying rule order is the first troubleshooting step.

Exam trap

Palo Alto Networks often tests the misconception that certificate issues are the primary cause of decryption failures, but in Palo Alto environments, rule order and policy evaluation are the most common first-step troubleshooting focus.

How to eliminate wrong answers

Option A is wrong because the decryption profile's 'decrypt' setting and forward proxy option are relevant for outbound SSL Forward Proxy decryption, not for inbound SSL Inbound Inspection, which uses a different configuration (the server's certificate). Option C is wrong because the server's certificate is not installed on the firewall for inbound inspection; instead, the firewall uses a copy of the server's private key and certificate (or a CA-signed certificate) to re-encrypt traffic, but the server's certificate is already on the server itself. Option D is wrong because the firewall does not need a 'valid certificate for inbound inspection' in the sense of a separate certificate; it needs the server's private key and certificate (or a certificate signed by a trusted CA) to perform SSL Inbound Inspection, but this is not the first troubleshooting step.

33
MCQhard

A firewall administrator notices that traffic from an internal user is being decrypted, but the user's browser shows a certificate warning. The firewall uses a CA certificate issued by the company's internal PKI. What is the most likely reason for the browser warning?

A.The decryption policy has the action 'decrypt' but no certificate profile.
B.The firewall's root CA certificate is not installed in the user's browser trusted root store.
C.The user's browser does not support TLS 1.2.
D.The server certificate is revoked.
AnswerB

Decryption requires the firewall to re-sign traffic with its own CA certificate. If that root CA is absent from the browser's trusted root store, the browser cannot validate the forged certificate chain and raises a warning, even though decryption itself succeeds.

Why this answer

The browser warning indicates that the firewall's decrypted traffic is being signed with a certificate that the browser does not trust. When a firewall performs SSL/TLS decryption using a CA certificate from the company's internal PKI, the browser will only trust the decrypted connections if the root CA certificate of that PKI is installed in the browser's trusted root certificate store. Without this trust anchor, the browser cannot validate the certificate chain presented by the firewall, resulting in a certificate warning.

Exam trap

The trap here is that candidates often confuse a missing trusted root CA certificate with a server certificate revocation or a decryption policy misconfiguration, failing to recognize that the browser warning specifically indicates a trust chain issue rather than a revocation or policy error.

How to eliminate wrong answers

Option A is wrong because a decryption policy with the action 'decrypt' but no certificate profile would cause the firewall to fail to decrypt traffic entirely, not produce a browser certificate warning after decryption. Option C is wrong because TLS 1.2 support is unrelated to certificate trust warnings; if the browser did not support TLS 1.2, the connection would fail or fall back to an older version, not show a certificate warning. Option D is wrong because server certificate revocation would cause a different error (e.g., CRL or OCSP failure) and is not related to the firewall's own CA certificate not being trusted by the browser.

34
MCQeasy

A firewall is configured for inbound inspection decryption. Which certificate must be installed on the firewall for this to work?

A.The client's certificate.
B.The server's certificate and private key.
C.A trusted CA certificate from the enterprise PKI.
D.The firewall's own self-signed certificate.
AnswerB

Inbound inspection decryption requires the firewall to present the server's certificate and its private key, enabling it to decrypt and re-encrypt traffic on the server's behalf. Without the matching private key, the firewall cannot complete the TLS handshake.

Why this answer

Inbound inspection decryption requires the firewall to act as a TLS proxy, intercepting and decrypting traffic destined for a protected server. To do this, the firewall must possess the server's certificate and its corresponding private key, allowing it to terminate the TLS connection from the client and re-encrypt traffic to the server. Without the private key, the firewall cannot decrypt the session.

Exam trap

The trap here is that candidates confuse inbound inspection decryption with SSL forward proxy decryption, where the firewall uses its own certificate or a CA-signed certificate, leading them to incorrectly choose Option C or D.

How to eliminate wrong answers

Option A is wrong because the client's certificate is used for client authentication (e.g., mutual TLS), not for inbound decryption; the firewall does not need the client's private key. Option C is wrong because a trusted CA certificate from the enterprise PKI is used to validate server certificates or to sign decryption certificates, but it does not provide the private key needed to decrypt traffic. Option D is wrong because the firewall's own self-signed certificate would not be trusted by clients for the server's domain, causing TLS handshake failures; it is typically used for forward proxy decryption, not inbound inspection.

35
MCQhard

Refer to the exhibit. An administrator configured SSH decryption, but the firewall logs an error. What is the most likely cause of this error?

A.The firewall does not have a certificate installed for SSH decryption.
B.The SSH session is using a cipher that is not supported by the firewall's decryption engine.
C.The SSH key exchange algorithm used by the client or server is not in the firewall's supported list.
D.The decryption policy is misconfigured because the service is set to 'any' instead of 'ssh'.
AnswerC

SSH decryption requires the firewall to negotiate the session using a supported key exchange algorithm. If the client or server offers only algorithms absent from the firewall's list, the handshake fails and decryption cannot proceed, producing the logged error.

Why this answer

The error message indicates 'unsupported key exchange algorithm'. SSH decryption requires the firewall to act as a proxy and re-encrypt the session. If the client or server uses a key exchange algorithm that the firewall does not support, decryption will fail.

The exhibit shows a policy for SSH decryption and a session, but the algorithm is not supported.

36
Multi-Selecthard

A security analyst needs to monitor decryption performance and identify sessions that are bypassing decryption due to policy or technical reasons. Which two monitoring tools or methods can provide this insight?

Select 2 answers
A.Decryption logs with filter 'decryption action not equal to decrypt'
B.System logs with filter 'decryption bypass'
C.ACC (Application Command Center) > Decryption Overview
D.Traffic logs with filter 'action equals decrypt' and 'reason equals bypass'
E.Packet capture on the decryption port
AnswersA, C

Decryption logs can be filtered to show sessions where decryption was not performed, including bypass reasons.

Why this answer

Decryption logs with a filter for 'decryption action not equal to decrypt' will show sessions that were not decrypted, including those bypassed due to policy (e.g., excluded URLs) or technical reasons (e.g., unsupported cipher suites). Option C is correct because the ACC > Decryption Overview provides a dashboard that visualizes decryption performance metrics, such as the number of sessions bypassed, decrypted, or failed, giving the analyst a high-level view of bypass activity.

Exam trap

The trap here is that candidates may confuse traffic logs with decryption logs, or assume that system logs contain decryption session details, when in fact decryption-specific logs and the ACC Decryption Overview are the correct sources for monitoring bypass activity.

37
Multi-Selectmedium

During SSL decryption, which three factors can cause the firewall to fail to decrypt a session or to bypass decryption?

Select 3 answers
A.The decryption rule has a schedule that is not currently active.
B.The SSH protocol is being used instead of SSL/TLS.
C.The firewall's decryption hardware accelerator is faulty.
D.The server certificate is signed by a CA not trusted by the firewall.
E.The session uses a cipher that is not listed in the decryption profile's allowed ciphers.
AnswersA, D, E

A rule with a schedule that is out of window will not match, so decryption will not apply.

Why this answer

A decryption rule with a schedule that is not currently active will not apply, causing the firewall to bypass decryption for the matching traffic. The firewall checks the schedule before attempting decryption, and if the schedule is inactive, the rule is effectively disabled, leading to a bypass.

Exam trap

The trap here is that candidates may think a faulty hardware accelerator (Option C) directly causes decryption failure, but Palo Alto Networks firewalls fall back to software decryption if hardware acceleration fails, so it does not result in a bypass or failure to decrypt.

38
MCQmedium

A company wants to decrypt all SSL/TLS traffic from internal users except traffic to financial sites. The firewall is placed as a forward proxy. Which policy configuration ensures that traffic to financial sites is not decrypted?

A.Create a decryption policy and use the 'exclude cache' option for financial sites.
B.Create a security policy that allows financial sites without decryption; then create a decryption policy with action 'no-decrypt' for those sites.
C.Create a decryption policy with action 'decrypt' and a source zone of internal; then create a decryption exemption for financial URLs.
D.Create a decryption policy with action 'no-decrypt' for traffic to financial sites, and a catch-all decryption policy with action 'decrypt' for all other traffic.
AnswerD

Policy rules are evaluated top-down, so the specific no-decrypt rule for financial sites must precede the catch-all decrypt rule. This ordering ensures matching financial traffic bypasses decryption, satisfying the requirement to exclude those sites while decrypting everything else.

Why this answer

It uses a specific 'no-decrypt' action in a decryption policy for financial sites, which explicitly excludes them from SSL/TLS decryption. A catch-all policy with 'decrypt' then ensures all other internal user traffic is decrypted. This approach directly aligns with the forward proxy requirement to decrypt all traffic except the specified financial sites.

Exam trap

The trap here is that candidates often confuse security policies with decryption policies, or mistakenly think that a 'decrypt' action with an exemption list is equivalent to a 'no-decrypt' policy, when in fact Palo Alto Networks requires a separate decryption policy with the 'no-decrypt' action for explicit exclusion.

How to eliminate wrong answers

Option A is wrong because the 'exclude cache' option is used to prevent caching of decrypted content, not to exclude traffic from decryption; it does not affect whether decryption occurs. Option B is wrong because a security policy alone cannot control decryption; decryption is governed by decryption policies, not security policies, and the order of policy evaluation requires a decryption policy to specify 'no-decrypt'. Option C is wrong because a decryption exemption is not a valid configuration in Palo Alto Networks firewalls; the correct method is to use a decryption policy with action 'no-decrypt'.

39
Multi-Selecthard

Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)

Select 2 answers
A.Use a self-signed certificate for decryption.
B.Decrypt all internal traffic including server-to-server.
C.Exclude traffic to financial and healthcare sites from decryption.
D.Decrypt all outbound traffic regardless of destination.
E.Install the firewall's CA certificate on all client devices.
AnswersC, E

Forward proxy decryption breaks the end-to-end trust model and exposes sensitive content, so regulatory and privacy obligations make financial and healthcare categories poor candidates for inspection. Excluding them from decryption preserves compliance and avoids legal exposure while still decrypting other traffic.

Why this answer

Option C is correct because privacy and compliance regulations (such as PCI-DSS, HIPAA, and GDPR) prohibit or restrict the interception of traffic to financial and healthcare sites, so these destinations should be added to the SSL Forward Proxy decryption exclusion list to avoid legal and privacy violations. Option E is correct because SSL Forward Proxy decryption requires the firewall to re-sign the server certificate with its own CA; for clients to trust this re-signed certificate and avoid certificate errors, the firewall's forward-trust CA certificate must be installed in the trusted root store of all client devices. Option A is not a best practice because using a self-signed certificate for decryption causes trust errors on clients and does not provide a manageable, trusted CA chain.

Option B is not a best practice because decrypting all internal server-to-server traffic is unnecessary, adds significant processing overhead, and can break applications that use certificate pinning or mutual TLS. Option D is not a best practice because decrypting all outbound traffic regardless of destination ignores privacy, compliance, and performance considerations, and traffic to sensitive categories should be excluded.

Exam trap

The trap is thinking that more decryption is always better; candidates may choose to decrypt all traffic, ignoring privacy, performance, and application compatibility issues.

40
MCQeasy

Refer to the exhibit. The firewall raises a certificate expiry warning for the decryption CA. Which action is required?

A.Renew the decryption CA certificate before expiry
B.Ignore the warning as it is only informational
C.Import a new server certificate
D.Disable decryption until renewal
AnswerA

Renewing the decryption CA certificate before expiry directly resolves the warning, since the firewall validates the CA's own validity period when performing SSL forward proxy decryption. An expired CA breaks the trust chain for all forged site certificates, so renewal preserves uninterrupted decryption. This satisfies the stem's requirement to clear the expiry warning.

Why this answer

The decryption CA certificate is used by the firewall to generate and sign internal server certificates for SSL decryption. When it expires, the firewall can no longer create new decryption certificates, causing SSL decryption to fail for new sessions. Renewing the decryption CA certificate before expiry ensures uninterrupted decryption and avoids certificate validation errors for clients.

Exam trap

Palo Alto Networks often tests the distinction between the decryption CA certificate (which must be renewed) and server certificates (which are imported for specific sites), leading candidates to mistakenly choose importing a new server certificate.

How to eliminate wrong answers

Option B is wrong because the certificate expiry warning is not merely informational; an expired decryption CA will break SSL decryption functionality, leading to service disruption. Option C is wrong because importing a new server certificate addresses individual server certificates, not the decryption CA certificate that signs them; the CA certificate must be renewed independently. Option D is wrong because disabling decryption until renewal is unnecessary and overly disruptive; the correct action is to proactively renew the CA certificate while the current one is still valid.

41
MCQeasy

An administrator wants to monitor which applications are being used on the network after SSL decryption. Which Palo Alto Networks feature provides detailed information about applications, including those that use SSL/TLS?

A.User-ID
B.SSL Decryption
C.App-ID
D.Content-ID
AnswerC

App-ID identifies applications traversing the network, even within encrypted traffic once decrypted. It provides detailed application information in logs and allows policy enforcement based on application. After decryption, App-ID can accurately identify applications that use SSL/TLS, such as file-sharing or social media apps.

Why this answer

App-ID is the Palo Alto Networks technology that identifies applications, including those that use SSL/TLS, after decryption. It provides visibility and control over applications. Content-ID, User-ID, and SSL Decryption serve different purposes: Content-ID enforces security, User-ID maps users, and SSL Decryption enables inspection.

Exam trap

The trap here is confusing the roles of App-ID and Content-ID, or thinking that SSL Decryption itself provides application details.

42
MCQeasy

A company wants to decrypt all SSL traffic from internal users to external websites. They have deployed a Palo Alto Networks firewall in forward proxy mode and installed a trusted root CA certificate on all endpoints. Users, however, are complaining about certificate errors when accessing HTTPS sites. Which configuration step is most likely missing?

A.The decryption profile is set to block sessions with untrusted certificates.
B.The firewall is performing inbound inspection instead of forward proxy.
C.The firewall's decryption certificate is not signed by the installed root CA.
D.No decryption profile is attached to the decryption rule.
AnswerC

For forward proxy decryption, the firewall presents a certificate to endpoints, which must chain to the trusted root CA installed on them. If the firewall's decryption certificate is signed by a different CA, endpoints reject it, producing the certificate errors users report.

Why this answer

In forward proxy decryption, the firewall generates a decryption certificate that must be signed by the trusted root CA installed on the endpoints. If the decryption certificate is self-signed or signed by a different CA, the browser will not trust it, causing certificate errors. The root CA certificate must be installed on all endpoints to establish a chain of trust for the firewall-generated certificates.

Exam trap

The trap here is that candidates often confuse the need for a decryption profile (Option D) with the fundamental requirement of a trusted root CA certificate, or they mistakenly think blocking untrusted certificates (Option A) is the cause of errors rather than a consequence of missing trust.

How to eliminate wrong answers

Option A is wrong because blocking sessions with untrusted certificates would prevent access entirely, not cause certificate errors; the complaint is about errors, not blocked access. Option B is wrong because inbound inspection is used for decrypting traffic destined to internal servers, not for outbound SSL traffic from internal users to external websites, which requires forward proxy mode. Option D is wrong because even without a decryption profile attached, the decryption rule would still apply default decryption settings; the missing step is the certificate trust chain, not the profile attachment.

43
MCQmedium

A network security administrator needs to confirm whether the firewall is actually decrypting outbound web traffic and which URLs are being decrypted. The administrator wants to see entries that explicitly show the decryption status of each session. Which log type and field combination should the administrator use?

A.Traffic log with the 'Session End Reason' field filtered for 'decrypt'
B.Threat log filtered by 'ssl-decryption' threat ID
C.System log filtered by subtype 'ssl-decrypt'
D.Decryption log with the 'Decryption Status' field and URL details
AnswerD

The Decryption log is specifically designed to record SSL/TLS decryption activity, including whether sessions were decrypted, the decryption policy that matched, and the affected URL or host. Filtering on Decryption Status lets the administrator confirm successful decryption and see which URLs were decrypted, which directly answers the requirement to verify actual decryption and identify decrypted URLs.

Why this answer

The Decryption log is the authoritative source for verifying SSL/TLS decryption. It records the decryption policy match, the decryption status of each session, and associated URL or host details, allowing an administrator to confirm that outbound web traffic is being decrypted and to see the specific URLs involved. Other log types either record security events, system events, or session termination reasons and do not provide per-session decryption confirmation.

Exam trap

The trap here is assuming that the Traffic log alone can confirm decryption, when actual decryption status and URL-level detail are recorded in the Decryption log.

44
MCQmedium

A security administrator needs to monitor which applications are being used over encrypted traffic. The firewall is configured to decrypt outbound SSL traffic. Which log type should the administrator review to see the decrypted application details?

A.Threat log
B.Traffic log
C.URL filtering log
D.Decryption log
AnswerB

The traffic log records all sessions, including those that are decrypted. After decryption, the firewall can identify the application (e.g., Facebook, Gmail) and log it in the traffic log. The traffic log also shows the decryption status (e.g., decrypted, no-decrypt) and any associated threats if further inspection is done. This is the primary log for monitoring application usage.

Why this answer

The traffic log is the central log for all sessions and includes application identification, even for decrypted traffic. After SSL decryption, the firewall can identify the application and log it in the traffic log. Other logs like threat or URL filtering are specialized and do not provide a complete view of application usage.

Exam trap

The trap here is assuming that a dedicated decryption log exists, when in fact decryption details are integrated into the traffic log.

45
MCQmedium

A network security administrator is configuring a Palo Alto Networks firewall to decrypt outbound HTTPS traffic. The administrator wants to ensure that the firewall can present a valid certificate to internal users for any website they visit, without manually importing each website's certificate. Which configuration is required to achieve this?

A.Enable SSL Inbound Inspection and configure a Forward Untrust certificate.
B.Enable SSL Forward Proxy and configure a Forward Untrust certificate.
C.Enable SSL Forward Proxy and configure a Forward Trust certificate.
D.Enable SSL Inbound Inspection and configure a Forward Trust certificate.
AnswerC

SSL Forward Proxy requires a Forward Trust certificate to sign the certificates presented to internal clients. This certificate must be trusted by the clients, and the firewall uses it to dynamically generate certificates for external sites, allowing decryption without importing each site's certificate.

Why this answer

SSL Forward Proxy decryption requires a Forward Trust certificate, which the firewall uses to generate certificates for external sites on the fly. This certificate must be trusted by internal clients. The Forward Untrust certificate is used to sign certificates for sites that the firewall does not trust, but it is not the primary certificate for decryption.

Inbound Inspection is for internal servers and requires their private keys.

Exam trap

The trap here is confusing SSL Forward Proxy with SSL Inbound Inspection, or mixing up the roles of Forward Trust and Forward Untrust certificates.

46
MCQmedium

A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The administrator wants to exclude employee access to healthcare portals from decryption to comply with privacy regulations, while still decrypting all other HTTPS traffic. Which decryption policy configuration should the administrator use?

A.Create a decryption policy rule with action 'no-decrypt' for the healthcare portal URLs, placed above the general decrypt rule.
B.Configure a URL Filtering profile to block the healthcare portals, preventing any access.
C.Add the healthcare portal IP addresses to the SSL Decryption Exclusion list under Device > Setup > Session.
D.Create a security policy rule with action 'allow' and attach a decryption profile that disables decryption for those URLs.
AnswerA

This is correct because decryption policies are evaluated top-down, and a no-decrypt rule for specific URLs ensures those sessions bypass decryption while all other HTTPS traffic is decrypted by the subsequent rule. This meets the privacy requirement without affecting general inspection.

Why this answer

Decryption policies are separate from security policies and are evaluated top-down. A no-decrypt rule for specific URLs, placed above a general decrypt rule, allows the administrator to exclude healthcare portals from decryption while decrypting all other HTTPS traffic. This satisfies privacy compliance without blocking access.

Exam trap

The trap here is confusing decryption policy with security policy or URL filtering, assuming that a security rule or URL filter can control decryption behavior.

47
MCQhard

Refer to the exhibit. A user reports that they receive a certificate warning when accessing https://example.com. The firewall is configured to decrypt SSL traffic. What is the most likely cause?

A.The web server's certificate is invalid and the firewall is not configured to block untrusted certificates.
B.The client device does not have the firewall's CA certificate installed in its trusted root store.
C.The decryption policy is not matching the traffic because the destination is not specified.
D.The firewall's decryption certificate is expired.
AnswerB

SSL decryption makes the firewall re-sign traffic with its own CA. If that CA certificate is absent from the client's trusted root store, the browser cannot validate the forged certificate chain and raises a warning, even though decryption itself succeeds.

Why this answer

The log shows an error 'Certificate is not trusted by client'. This typically occurs when the firewall's decryption CA certificate is not installed in the client's trusted root store. The firewall's certificate is valid, but the client does not trust it.

48
Multi-Selectmedium

Which THREE actions can be performed in a decryption policy? (Choose three.)

Select 3 answers
A.App-ID
B.Allow
C.No-decrypt
D.Block
E.Decrypt
AnswersC, D, E

No-decrypt lets the firewall forward matching sessions without performing decryption, preserving privacy for traffic that policy forbids inspecting. This satisfies the stem's requirement for a decryption policy action, since Palo Alto decryption policies define whether traffic is decrypted, bypassed, or blocked, and no-decrypt is one of the three available actions.

Why this answer

In a Palo Alto Networks decryption policy, the three supported actions are No-decrypt (C), Block (D), and Decrypt (E). No-decrypt (C) is correct because it lets traffic bypass decryption, which is used for traffic that cannot or should not be decrypted, such as pinned or unsupported cipher suites. Block (D) is correct because the policy can drop sessions outright, for example to enforce that certain categories or applications must be decrypted or denied.

Decrypt (E) is correct because it is the core action that applies SSL/TLS decryption to matching sessions. App-ID (A) is not an action but a matching criterion/classification used in the policy rule, and Allow (B) is a security policy action, not a decryption policy action.

Exam trap

The trap here is that candidates may confuse security policy actions (like Allow) with decryption policy actions. Decryption policy supports three actions: Decrypt, No-decrypt, and Block. Options A (App-ID) and B (Allow) are not decryption policy actions.

49
Multi-Selectmedium

Which THREE factors should be considered when deciding which traffic to decrypt? (Select exactly three.)

Select 3 answers
A.Privacy regulations
B.The cost of SSL certificates
C.Performance impact of decryption
D.User productivity
E.Compliance requirements
AnswersA, C, E

Privacy laws may prohibit decryption of sensitive personal data.

Why this answer

Privacy regulations such as GDPR, HIPAA, or PCI DSS often restrict the decryption of traffic containing personally identifiable information (PII) or protected health information (PHI). Decrypting such traffic without proper safeguards can lead to legal penalties and data breach exposure. Palo Alto Networks firewalls can apply decryption policies that exclude traffic to specific URL categories or IP ranges to remain compliant with these regulations.

Exam trap

Palo Alto Networks often tests the misconception that cost or user productivity are primary factors in decryption decisions, when in reality the exam focuses on privacy regulations, performance impact, and compliance requirements as the three key considerations.

50
Multi-Selectmedium

A security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The administrator wants to ensure that the firewall can generate certificates for decrypted sites and that internal users do not receive browser warnings. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Install the forward trust CA certificate as a trusted root in the internal users' browser or operating system trust stores.
B.Enable SSL Forward Proxy in a decryption policy rule that matches outbound HTTPS traffic.
C.Generate or import a forward trust certificate and its private key on the firewall.
D.Import the forward untrust certificate into the firewall's trust store for the destination servers.
E.Configure a decryption profile to block sessions with unsupported cipher suites.
AnswersA, C

For clients to accept the re-signed certificates without warnings, the forward trust CA certificate must be trusted by the endpoint. Distributing it via Group Policy, MDM, or manual installation ensures the certificate chain is trusted. Without this step, users see certificate warnings even though decryption is working on the firewall.

Why this answer

Successful SSL Forward Proxy decryption requires the firewall to have a forward trust certificate and private key to sign re-issued certificates, and clients must trust the forward trust CA to accept those certificates silently. The decryption policy rule and decryption profile are important but do not directly address certificate generation and client trust.

Exam trap

The trap here is confusing the forward trust certificate with the forward untrust certificate, or assuming that firewall-side configuration alone prevents client warnings.

51
MCQmedium

Refer to the exhibit. A firewall log shows a decryption failure for a session. What is the most probable cause?

A.The firewall's system time is ahead of the certificate's validity start
B.The server's certificate is expired
C.The decryption profile rejects self-signed certificates
D.The client's system time is behind
AnswerA

Certificate validity is evaluated against the firewall's clock. If system time precedes the certificate's notBefore value, the certificate is not yet valid, so the firewall rejects it and the session decryption fails, matching the logged decryption failure.

Why this answer

When the firewall's system time is ahead of the certificate's validity start (the 'not before' date), the firewall considers the certificate as not yet valid. During SSL/TLS decryption, the firewall validates the server certificate's time constraints against its own system clock. If the firewall's clock is ahead, the certificate appears to be from the future, causing a decryption failure even though the server and client clocks may be correct.

Exam trap

Palo Alto Networks often tests the distinction between certificate expiry (notAfter) and certificate not-yet-valid (notBefore), where candidates mistakenly assume any decryption failure is due to an expired certificate rather than a clock skew issue.

How to eliminate wrong answers

Option B is wrong because an expired server certificate (past the 'not after' date) would also cause a decryption failure, but the scenario specifically describes the firewall's time being ahead, which points to the 'not before' issue, not expiry. Option C is wrong because the question does not mention a decryption profile rejecting self-signed certificates; the log shows a decryption failure, not a policy-based rejection. Option D is wrong because the client's system time is irrelevant to the firewall's decryption process; the firewall uses its own system clock to validate certificate validity, not the client's clock.

52
MCQhard

An administrator notices that the firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which feature should be used to selectively bypass decryption for certain traffic?

A.Configure a decryption profile to disable decryption for untrusted certificates.
B.Enable hardware acceleration for SSL decryption.
C.Decryption policy with 'no-decrypt' action for specific URL categories.
D.SSL decryption exclusion based on source IP address.
AnswerC

Creating decryption policy rules with 'no-decrypt' for categories that are not critical for inspection (e.g., streaming media, social networking) reduces the volume of decrypted traffic, thereby lowering CPU load. This allows the firewall to focus resources on decrypting traffic that poses higher risk, balancing security and performance.

Why this answer

To reduce CPU load from SSL decryption without disabling it entirely, administrators should create decryption policy rules with the 'no-decrypt' action for specific URL categories or traffic that is less critical for inspection. This selective bypass reduces the volume of decrypted sessions, lowering CPU utilization while maintaining decryption for high-risk traffic.

Exam trap

The trap here is thinking that hardware acceleration or decryption profiles are the primary means to reduce CPU load from decryption, when selective bypass via no-decrypt rules is the direct method.

53
MCQeasy

A Palo Alto firewall administrator wants to monitor SSL decryption efficiency. Which log type provides the most detailed information about decryption actions and reasons for not decrypting?

A.System logs
B.Decryption logs
C.Traffic logs
D.Threat logs
AnswerB

Decryption logs record each session's decryption outcome, including the specific reason a flow was not decrypted, such as unsupported cipher or exempted category. They provide the granular per-session detail needed to measure SSL decryption efficiency, unlike traffic or threat logs.

Why this answer

Decryption logs are specifically designed to record detailed information about SSL decryption actions, including whether traffic was decrypted, not decrypted, or bypassed, along with the exact reason (e.g., unsupported cipher, certificate mismatch, excluded category). This granularity is essential for monitoring decryption efficiency and troubleshooting decryption policies.

Exam trap

The trap here is that candidates may confuse Traffic logs (which show a decryption flag) with Decryption logs (which provide the detailed reason), leading them to choose Traffic logs as the most detailed source when Decryption logs are the correct answer.

How to eliminate wrong answers

Option A is wrong because System logs capture system-level events (e.g., reboots, HA state changes, license expiration) and do not contain per-session decryption decisions or reasons for not decrypting. Option C is wrong because Traffic logs record session metadata (source/destination IP, ports, application, bytes) and may indicate if decryption was applied via a flag, but they lack the specific reason codes for why decryption was skipped or failed. Option D is wrong because Threat logs focus on detected threats (e.g., malware, exploits, spyware) and do not provide decryption-specific actions or exclusion reasons.

54
MCQmedium

A company has a decryption policy that decrypts all traffic except for traffic to financial sites. However, users report that some financial sites are still being decrypted. What should the admin check first?

A.The decryption policy rule order
B.The firewall's system logs
C.The certificate revocation status
D.The SSL/TLS service profile settings
AnswerA

Decryption policy rules are evaluated top-down, so a broader decrypt rule placed above the financial-site no-decrypt rule matches first and decrypts that traffic. Checking rule order identifies this precedence conflict before investigating certificates or profiles.

Why this answer

The decryption policy is evaluated in order from top to bottom, and the first matching rule is applied. If a rule that decrypts traffic is placed above the rule that excludes financial sites, traffic to those sites will be decrypted before reaching the exclusion rule. The admin should check the rule order to ensure the financial site exclusion rule is positioned above any decrypting rules.

Exam trap

The trap here is that candidates often assume the issue is with certificates or logs, overlooking the fundamental first-match policy evaluation order that directly causes the described behavior.

How to eliminate wrong answers

Option B is wrong because system logs record events after policy enforcement, but they do not affect the policy order; the issue is a misconfiguration in the policy sequence, not a logging deficiency. Option C is wrong because certificate revocation status (CRL/OCSP) is checked during SSL/TLS handshake validation, not for determining which traffic to decrypt; it is unrelated to policy rule ordering. Option D is wrong because SSL/TLS service profile settings define cipher suites and protocol versions for decryption, not the traffic matching logic that determines which sites are decrypted or excluded.

Ready to test yourself?

Try a timed practice session using only Decryption Monitoring questions.