PCNSE Decryption and SSL Inspection Practice Question
A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?
⚠ Common exam trap
Test-takers frequently confuse certificate expiration with other certificate validation checks like untrusted issuer or unknown status; each has a separate setting in the decryption profile.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block sessions with expired certificates under SSL Forward Proxy settings.
Within a decryption profile, the SSL Forward Proxy settings include an option to block sessions when the server certificate is expired. Enabling this ensures that the firewall checks the validity period of the server's certificate and drops the connection if it has expired. This is the correct setting to meet the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block sessions with expired certificates under SSL Forward Proxy settings.
Why this is correct
The decryption profile includes an option to block sessions when the server certificate is expired. Enabling this setting causes the firewall to drop the connection if the server's certificate has expired, preventing users from accessing potentially insecure sites. This directly addresses the requirement to block expired certificates.
- ✗
Block sessions with unknown certificate status under SSL Forward Proxy settings.
Why it's wrong here
This setting blocks sessions when the certificate's revocation status cannot be determined (e.g., OCSP or CRL check fails). It does not address certificate expiration. While it enhances security, it does not meet the specific requirement to block expired certificates.
- ✗
Block sessions with untrusted issuers under SSL Forward Proxy settings.
Why it's wrong here
Blocking untrusted issuers will drop sessions when the server certificate is signed by an untrusted CA, but it does not specifically check for expiration. An expired certificate from a trusted CA would still be allowed if only this setting is enabled. The requirement is to block expired certificates, so this setting alone is insufficient.
- ✗
Block sessions with client authentication failures under SSL Forward Proxy settings.
Why it's wrong here
This setting applies to client certificate authentication failures, not server certificate expiration. It is used when the firewall requires clients to present certificates. It is unrelated to the scenario of blocking expired server certificates, so it would not achieve the desired outcome.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.