Courseiva

PCNSA Decryption and Monitoring Practice Question

Which TWO of the following are best practices for configuring SSL Forward Proxy decryption? (Choose two.)

⚠ Common exam trap

The trap is thinking that more decryption is always better; candidates may choose to decrypt all traffic, ignoring privacy, performance, and application compatibility issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exclude traffic to financial and healthcare sites from decryption.

Option C is correct because privacy and compliance regulations (such as PCI-DSS, HIPAA, and GDPR) prohibit or restrict the interception of traffic to financial and healthcare sites, so these destinations should be added to the SSL Forward Proxy decryption exclusion list to avoid legal and privacy violations. Option E is correct because SSL Forward Proxy decryption requires the firewall to re-sign the server certificate with its own CA; for clients to trust this re-signed certificate and avoid certificate errors, the firewall's forward-trust CA certificate must be installed in the trusted root store of all client devices. Option A is not a best practice because using a self-signed certificate for decryption causes trust errors on clients and does not provide a manageable, trusted CA chain. Option B is not a best practice because decrypting all internal server-to-server traffic is unnecessary, adds significant processing overhead, and can break applications that use certificate pinning or mutual TLS. Option D is not a best practice because decrypting all outbound traffic regardless of destination ignores privacy, compliance, and performance considerations, and traffic to sensitive categories should be excluded.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a self-signed certificate for decryption.

    Why it's wrong here

    A self-signed certificate is untrusted by clients, so browsers flag every decrypted session and the proxy cannot validate upstream servers. It is tempting because it is quick to generate, but it suits only internal lab testing where no public trust chain is required.

  • ✗

    Decrypt all internal traffic including server-to-server.

    Why it's wrong here

    Decrypting internal server-to-server traffic adds inspection overhead and exposes east-west data without security benefit, since those flows are already trusted. It is tempting for complete visibility, and it would be correct for inspecting traffic crossing a trust boundary, not internal flows.

  • ✓

    Exclude traffic to financial and healthcare sites from decryption.

    Why this is correct

    Forward proxy decryption breaks the end-to-end trust model and exposes sensitive content, so regulatory and privacy obligations make financial and healthcare categories poor candidates for inspection. Excluding them from decryption preserves compliance and avoids legal exposure while still decrypting other traffic.

  • ✗

    Decrypt all outbound traffic regardless of destination.

    Why it's wrong here

    Decrypting every outbound flow regardless of destination breaks privacy law, exposes sensitive categories and overloads the firewall. It is tempting as blanket visibility, and it would be correct only for a deliberately scoped category, not all destinations.

  • ✓

    Install the firewall's CA certificate on all client devices.

    Why this is correct

    Forward proxy decryption requires clients to trust the firewall's signing CA; otherwise every re-signed certificate triggers a browser warning. Distributing the firewall's CA certificate to all client trust stores via group policy or MDM establishes that chain of trust and enables transparent decryption.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on PCNSA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to decrypt all SSL traffic from internal users to external websites. They have deployed a Palo Alto Networks firewall in forward proxy mode and installed a trusted root CA certificate on all endpoints. Users, however, are complaining about certificate errors when accessing HTTPS sites. Which configuration step is most likely missing?

easy
  • A.The decryption profile is set to block sessions with untrusted certificates.
  • B.The firewall is performing inbound inspection instead of forward proxy.
  • ✓ C.The firewall's decryption certificate is not signed by the installed root CA.
  • D.No decryption profile is attached to the decryption rule.

Why C: In forward proxy decryption, the firewall generates a decryption certificate that must be signed by the trusted root CA installed on the endpoints. If the decryption certificate is self-signed or signed by a different CA, the browser will not trust it, causing certificate errors. The root CA certificate must be installed on all endpoints to establish a chain of trust for the firewall-generated certificates.

Variation 2. A company implements SSL Forward Proxy decryption. Users report that some internal applications fail to load after deployment. The firewall is configured with a CA-signed certificate for decryption. What is the most likely cause of the application failures?

medium
  • A.The decryption policy uses 'No Decrypt' for the internal application's URL category.
  • B.The decryption policy is set to 'Decrypt' for all traffic, causing performance bottlenecks.
  • ✓ C.The firewall's CA certificate is not installed in the trusted root store on user endpoints.
  • D.The firewall is configured to decrypt traffic from the internal zone, but not the external zone.

Why C: SSL Forward Proxy decryption requires the firewall's CA certificate to be trusted by client endpoints. When the firewall generates a new certificate for the internal application's server, the client must trust the firewall's CA to avoid certificate validation errors. Without the CA in the trusted root store, browsers and applications will reject the connection, causing failures for internal applications that rely on SSL/TLS.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.