PCNSE Decryption and SSL Inspection Practice Question
A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?
⚠ Common exam trap
The trap here is assuming that a trusted public CA certificate guarantees successful decryption, overlooking client-side pinning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The website uses certificate pinning, causing the client to reject the firewall's forged certificate.
Certificate pinning causes clients to expect a specific certificate or public key for a website. When SSL Forward Proxy decryption is enabled, the firewall presents a forged certificate, which the client rejects due to pinning. This results in access failures. Exempting such sites from decryption is a typical solution. Other causes like expired certificates or licensing are not applicable here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall's decryption profile is blocking the session because the website's certificate is expired.
Why it's wrong here
The scenario states the website's certificate is signed by a trusted public CA, implying it is valid. If the certificate were expired, the firewall would block, but the issue is more likely due to client-side pinning. The trusted CA status suggests the certificate itself is not the problem.
- ✗
The firewall's SSL decryption license has expired, causing it to block decrypted sessions.
Why it's wrong here
SSL decryption does not require a separate license on Palo Alto Networks firewalls. An expired license would not cause selective blocking of one website. The issue is specific to one site, indicating a client-side or application-specific problem like pinning.
- ✗
The website requires TLS 1.3, which is not supported by the firewall's decryption profile.
Why it's wrong here
PAN-OS supports TLS 1.3 decryption. While there can be compatibility issues, the scenario does not mention TLS version. The most likely cause is certificate pinning, as it is a common reason for access failures after decryption is enabled, especially for specific sites.
- ✓
The website uses certificate pinning, causing the client to reject the firewall's forged certificate.
Why this is correct
Certificate pinning in applications or browsers causes them to expect a specific certificate or public key. When the firewall performs SSL Forward Proxy decryption, it presents a forged certificate, which the client rejects if pinning is enforced. This leads to access failures. Exempting such sites from decryption is a common workaround.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.