PCNSE Decryption and SSL Inspection Practice Question
Exhibit
Refer to the exhibit. admin@PA-5000> show decryption statistics Total Decrypted Packets: 12345 Total SSL Handshake Attempts: 1000 Successful Handshakes: 950 Failed Handshakes: 50 - Decryption policy not matched: 20 - Certificate validation failure: 15 - Unsupported cipher: 10 - Other: 5
A network administrator observes that some SSL connections are failing to be decrypted. Based on the exhibit, what is the most likely reason for the majority of the failures?
⚠ Common exam trap
The trap here is that candidates often focus on certificate or cipher issues, but the PCNSE exam emphasizes that decryption is policy-driven, and the most common failure is a missing or misordered decryption rule, not a technical handshake problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No decryption policy rule matches the traffic
The exhibit shows a decryption policy with no matching rules for the failing SSL connections. When no decryption policy rule matches, the firewall forwards the traffic without decrypting it, which can cause failures if the firewall is configured to block non-decrypted traffic or if the application requires inspection. This is the most common cause of decryption failures in Palo Alto Networks firewalls, as decryption is policy-driven and traffic must match a rule to be decrypted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall's certificate is not trusted by clients
Why it's wrong here
Certificate validation failures are only 15, lower than policy not matched.
- ✓
No decryption policy rule matches the traffic
Why this is correct
The statistics show 20 failures due to policy not matched, which is the highest cause.
- ✗
The client and server negotiate an unsupported cipher
Why it's wrong here
Unsupported cipher failures are only 10, lower than policy not matched.
- ✗
The decryption profile is misconfigured
Why it's wrong here
Profile misconfiguration would likely manifest as certificate validation or other errors, not specifically policy not matched.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.