Courseiva
Troubleshoot →hardMultiple Choice

PCNSE Troubleshoot Practice Question

A network security engineer is troubleshooting why a user's session to a SaaS application is being decrypted by SSL Forward Proxy but then immediately reset. The engineer checks the session details and sees the session end reason as 'tcp-rst-from-server'. Packet capture on the firewall shows that the server is sending a TCP RST after the client sends a TLS Client Hello. The firewall's decryption profile is configured to block sessions with untrusted issuers. What is the most likely cause of the reset?

⚠ Common exam trap

The trap here is assuming that any reset during SSL decryption is caused by certificate trust issues on the client or firewall side, when in fact the server may be rejecting the connection due to decryption-induced changes in the TLS handshake.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server is rejecting the connection because the SNI in the Client Hello does not match the server's expected hostname, or the server requires mutual TLS authentication.

The correct answer is that the server is rejecting the connection due to SNI mismatch or mutual TLS requirements. When SSL Forward Proxy decrypts, it acts as a man-in-the-middle, and the server may see a different SNI or lack a client certificate, causing it to reset the connection. This is consistent with the observed 'tcp-rst-from-server' and the server sending a RST after receiving the Client Hello.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The server is rejecting the connection because the SNI in the Client Hello does not match the server's expected hostname, or the server requires mutual TLS authentication.

    Why this is correct

    When SSL Forward Proxy decrypts traffic, it generates a new Client Hello to the server. If the server expects a specific SNI that matches its certificate, or if it requires client certificate authentication (mutual TLS), the server may reject the connection with a TCP RST. This is a common issue when decryption interferes with server-side validation. The session end reason 'tcp-rst-from-server' confirms the server initiated the reset.

  • ✗

    The firewall's forward trust certificate is not trusted by the client, causing the client to reset the connection.

    Why it's wrong here

    If the client did not trust the firewall's forward trust certificate, the client would send a TLS alert or reset the connection, resulting in 'tcp-rst-from-client'. The session end reason indicates the reset came from the server, so the issue is on the server side or in the decrypted traffic reaching the server, not the client's trust of the forward trust certificate.

  • ✗

    The server is using a self-signed certificate that is not trusted by the firewall's forward trust certificate.

    Why it's wrong here

    A self-signed server certificate would cause the firewall to block the session if the decryption profile is set to block untrusted issuers, but the block would typically be initiated by the firewall and result in a session end reason like 'policy-deny' or 'decrypt-error', not 'tcp-rst-from-server'. The server sending a RST after receiving the Client Hello suggests the server itself is rejecting the connection, possibly due to the client's TLS version or cipher suites.

  • ✗

    The server is configured to require TLS 1.3, but the firewall's decryption profile is set to only allow TLS 1.2, causing the server to reset the connection.

    Why it's wrong here

    If the firewall only allows TLS 1.2 and the server requires TLS 1.3, the firewall would likely block the session during the TLS handshake and generate a decryption error, not allow the Client Hello to reach the server. The fact that the server receives the Client Hello and responds with a RST suggests the server is rejecting the connection due to the content of the Client Hello, such as an unsupported cipher suite or SNI mismatch.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.