Courseiva

PCNSE Decryption and SSL Inspection Practice Question

A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?

⚠ Common exam trap

The trap here is assuming that the internal CA certificate itself can be used as the Forward Trust certificate, when in fact a separate subordinate certificate must be generated and signed by the CA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a certificate signing request (CSR) for the Forward Trust certificate, have it signed by the internal CA, and import the signed certificate.

For SSL Forward Proxy decryption, the firewall must have a Forward Trust certificate that is trusted by internal clients. This certificate is typically a subordinate certificate signed by the organization's internal CA. The firewall generates a CSR, the CA signs it, and the resulting certificate is imported and configured as the Forward Trust certificate. This allows the firewall to dynamically generate certificates for external sites that clients will trust.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate a new self-signed certificate on the firewall and assign it as the Forward Trust certificate.

    Why it's wrong here

    Generating a new self-signed certificate would not leverage the company's existing internal CA, which is already trusted by internal users. The Forward Trust certificate must be signed by a CA that clients trust; using a self-signed certificate would cause browser warnings unless that certificate is also distributed to all clients. This approach does not meet the requirement of using the company's internal CA.

  • ✓

    Create a certificate signing request (CSR) for the Forward Trust certificate, have it signed by the internal CA, and import the signed certificate.

    Why this is correct

    This is the correct process: the firewall generates a CSR for the Forward Trust certificate, which is then signed by the internal CA. The signed certificate is imported and designated as the Forward Trust certificate. This ensures that the firewall can dynamically sign website certificates that clients trust because the internal CA is already trusted by them.

  • ✗

    Assign the internal CA certificate directly as the Forward Trust certificate without generating a CSR.

    Why it's wrong here

    The Forward Trust certificate must be a separate certificate that the firewall uses to sign other certificates. The CA certificate itself cannot be used directly as the Forward Trust certificate because it is typically used only for signing subordinate certificates. Using the CA certificate directly would not allow proper certificate chain construction and may cause validation issues.

  • ✗

    Import the internal CA's private key and certificate into the firewall and designate it as the Forward Trust certificate.

    Why it's wrong here

    Importing the CA's private key and certificate would allow the firewall to act as the CA itself, but this is not a recommended practice due to security risks. The Forward Trust certificate should be a subordinate certificate signed by the CA, not the CA itself. This option would technically work but violates best practices and is not the required configuration.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.