Courseiva
Decryption and SSL InspectionmediumMultiple ChoiceObjective-mapped

PCNSE Decryption and SSL Inspection Practice Question

Exhibit

Refer to the exhibit.

admin@PA-5000> show decryption statistics

Total Decrypted Packets: 12345
Total SSL Handshake Attempts: 1000
Successful Handshakes: 950
Failed Handshakes: 50
  - Decryption policy not matched: 20
  - Certificate validation failure: 15
  - Unsupported cipher: 10
  - Other: 5

A network administrator observes that some SSL connections are failing to be decrypted. Based on the exhibit, what is the most likely reason for the majority of the failures?

⚠ Common exam trap

The trap here is that candidates often focus on certificate or cipher issues, but the PCNSE exam emphasizes that decryption is policy-driven, and the most common failure is a missing or misordered decryption rule, not a technical handshake problem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

No decryption policy rule matches the traffic

The exhibit shows a decryption policy with no matching rules for the failing SSL connections. When no decryption policy rule matches, the firewall forwards the traffic without decrypting it, which can cause failures if the firewall is configured to block non-decrypted traffic or if the application requires inspection. This is the most common cause of decryption failures in Palo Alto Networks firewalls, as decryption is policy-driven and traffic must match a rule to be decrypted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The firewall's certificate is not trusted by clients

    Why it's wrong here

    Certificate validation failures are only 15, lower than policy not matched.

  • No decryption policy rule matches the traffic

    Why this is correct

    The statistics show 20 failures due to policy not matched, which is the highest cause.

  • The client and server negotiate an unsupported cipher

    Why it's wrong here

    Unsupported cipher failures are only 10, lower than policy not matched.

  • The decryption profile is misconfigured

    Why it's wrong here

    Profile misconfiguration would likely manifest as certificate validation or other errors, not specifically policy not matched.

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.