Courseiva
Decryption and SSL InspectionmediumMultiple ChoiceObjective-mapped

PCNSE Decryption and SSL Inspection Practice Question

A company has deployed SSL Inbound Inspection to inspect HTTPS traffic to their internal web server hosting a custom application that requires mutual TLS authentication. The firewall is configured with a decryption policy that includes the server's certificate and the action 'decrypt'. The web server is configured to request client certificates. After implementation, users report that the application fails to authenticate them. The firewall logs show that SSL handshake with the client completes successfully, but the server never receives the client certificate during the handshake. The administrator has verified that the decryption policy is active and the server certificate is correctly imported. What is the most likely cause of this issue?

⚠ Common exam trap

Palo Alto Networks often tests the distinction between SSL Forward Proxy and SSL Inbound Inspection, and candidates mistakenly assume that client certificates are automatically forwarded in inbound scenarios, when in fact they require explicit configuration in the decryption profile.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The firewall is not configured to forward client certificates to the server.

In SSL Inbound Inspection, the firewall acts as a man-in-the-middle, terminating the client's SSL connection and then initiating a new SSL connection to the server. By default, the firewall does not forward the client certificate from the original client handshake to the server. To enable mutual TLS authentication, the administrator must explicitly configure the firewall to forward client certificates, typically via a Decryption Profile setting. Since the logs show a successful handshake with the client but the server never receives the client certificate, the missing forwarding configuration is the most likely cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The decryption policy is set to 'no-decrypt' for the application's traffic.

    Why it's wrong here

    If no-decrypt, the traffic would not be inspected, and the client certificate would reach the server.

  • The client certificates are not trusted by the firewall.

    Why it's wrong here

    The firewall does not need to trust client certificates for inbound inspection; it only forwards them.

  • The firewall's SSL Inbound Inspection profile is set to 'passive' mode.

    Why it's wrong here

    There is no 'passive' mode for SSL Inbound Inspection; the firewall fully terminates and re-originates connections.

  • The firewall is not configured to forward client certificates to the server.

    Why this is correct

    In SSL Inbound Inspection, the firewall must be configured to forward client certificates in the decryption profile; otherwise, it does not pass them.

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.