Courseiva
Troubleshoot →mediumMultiple Choice

PCNSE Troubleshoot Practice Question

A network engineer is troubleshooting why a Palo Alto Networks firewall is not decrypting SSH traffic even though an SSL Forward Proxy decryption policy is configured for the internal zone. The engineer confirms that the SSH traffic matches the decryption policy and that the forward trust and untrust certificates are installed and valid. What is the most likely reason the SSH traffic is not being decrypted?

⚠ Common exam trap

The trap here is assuming that SSL Forward Proxy can decrypt any encrypted traffic, including SSH, without recognizing that SSH requires a distinct SSH Proxy decryption policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSL Forward Proxy decryption does not support SSH; SSH decryption requires SSH Proxy.

SSH is not an SSL/TLS protocol, so SSL Forward Proxy cannot decrypt it. Palo Alto Networks firewalls use SSH Proxy to decrypt and inspect SSH traffic, which requires a separate decryption policy and configuration. Since only SSL Forward Proxy is configured, the SSH traffic remains encrypted even if the policy matches. The correct solution is to configure SSH Proxy decryption for the SSH traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The decryption policy is not matching because the SSH application is not recognized due to encryption.

    Why it's wrong here

    App-ID can identify SSH even when encrypted, based on protocol behavior and patterns. The decryption policy would match if SSH is correctly identified. The lack of decryption is not because App-ID fails, but because SSL Forward Proxy cannot decrypt SSH; SSH Proxy is required for that purpose.

  • ✓

    SSL Forward Proxy decryption does not support SSH; SSH decryption requires SSH Proxy.

    Why this is correct

    SSH is not an SSL/TLS-based protocol, so SSL Forward Proxy cannot decrypt it. Palo Alto Networks firewalls provide SSH Proxy to decrypt and inspect SSH traffic. This requires a separate SSH Proxy decryption policy and a forward trust certificate. Since the engineer only configured SSL Forward Proxy, the SSH traffic remains encrypted and is not decrypted.

  • ✗

    The decryption policy is not applied because the SSH traffic is using a non-standard port.

    Why it's wrong here

    Decryption policies are not port-based; they match on application, source, destination, and other criteria. Even if SSH is on a non-standard port, the App-ID engine can identify it as SSH, and the decryption policy would still apply if configured correctly. The issue is not the port but the decryption type.

  • ✗

    The forward trust certificate is not trusted by the SSH client, so the firewall bypasses decryption.

    Why it's wrong here

    SSL Forward Proxy decryption does not apply to SSH, so the trust relationship of the forward trust certificate is irrelevant. The firewall would not attempt to decrypt SSH using SSL Forward Proxy regardless of certificate trust. The failure is due to the protocol mismatch, not certificate validation.

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.