Courseiva
Securing Traffic →hardMultiple Select

PCNSA Securing Traffic Practice Question

Which THREE components are required to successfully decrypt outbound SSL traffic using forward proxy? (Choose three.)

⚠ Common exam trap

The trap is assuming the firewall needs the destination server's private key or certificate to decrypt — candidates who don't understand MITM re-signing often pick those options instead of the correct CA/policy/profile trio.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A root CA certificate installed in the trusted root store on client devices.

Option A is correct because SSL forward proxy decryption works by having the firewall/proxy re-sign the destination server's certificate with its own CA; clients must trust that CA, so the root CA certificate must be installed in the trusted root store on client devices. Option D is correct because a decryption policy rule is what actually matches the outbound traffic (by source, destination, URL category, service, etc.) and instructs the proxy to decrypt it rather than bypass it. Option E is correct because a decryption profile defines the forward proxy certificate (the CA certificate and key) used to generate the impersonated server certificates and enforces related SSL settings. Option B is not required because the proxy does not need the destination servers' private keys; it establishes its own separate TLS sessions with the client and the server. Option C is not required because the proxy obtains the destination server's certificate dynamically during the handshake and generates a substitute certificate signed by its own CA, rather than needing a pre-provisioned copy of each server certificate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A root CA certificate installed in the trusted root store on client devices.

    Why this is correct

    SSL forward proxy interception requires the firewall to present certificates signed by a CA the client already trusts. Installing the root CA certificate in each client's trusted root store establishes that chain of trust, satisfying the prerequisite for the firewall to re-sign outbound server certificates and decrypt the session.

  • ✗

    The private key of each destination server.

    Why it's wrong here

    The proxy cannot possess destination servers' private keys; it decrypts using its own certificate and key, then re-encrypts. It is tempting because decryption requires a private key, and would be correct when decrypting traffic terminating on a server you actually control.

  • ✗

    The server certificate for each destination server.

    Why it's wrong here

    The forward proxy decrypts by presenting its own certificate to the client, so destination server certificates are unnecessary. It is tempting because certificates are integral to TLS, and would be correct when the firewall must verify the identity of each backend server it connects to.

  • ✓

    A decryption policy rule that matches the traffic to be decrypted.

    Why this is correct

    A decryption policy rule defines which sessions the firewall intercepts and decrypts, matching by source, destination, user, URL category or application. Without it, outbound SSL traffic bypasses decryption entirely, so the forward proxy cannot present its certificate or inspect the encrypted payload.

  • ✓

    A decryption profile that specifies the forward proxy certificate (CA certificate).

    Why this is correct

    A decryption profile must reference the forward proxy's CA certificate so the firewall can re-sign intercepted sessions and present a trusted certificate to the client. Without this, browsers reject the forged certificate and TLS inspection fails, so the profile satisfies the requirement for a usable decryption certificate.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.