PCNSE Decryption and SSL Inspection Practice Question
A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?
⚠ Common exam trap
The trap here is assuming that the self-signed certificate of the website is the direct cause, when the real issue is the client's trust of the firewall's forward trust certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall's forward trust certificate is not trusted by the client, causing a certificate warning that prevents access.
The most likely cause is that the client does not trust the firewall's forward trust certificate. When SSL Forward Proxy decryption is enabled, the firewall re-signs the website's certificate with its forward trust certificate. If the client does not trust the CA that issued the forward trust certificate, it will display a warning and may block access. This is a common oversight when deploying decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall's forward trust certificate is not trusted by the client, causing a certificate warning that prevents access.
Why this is correct
When the firewall decrypts SSL traffic, it presents a certificate signed by its forward trust certificate. If the client does not trust the issuing CA, the browser will show a certificate warning and may block access. This is a common issue when the forward trust CA is not imported into the client's trusted root store. The self-signed nature of the website's certificate may trigger the firewall to use the forward untrust certificate, but the client trust of the firewall's certificate is the critical factor.
- ✗
The website's certificate is not trusted by the firewall, so the firewall blocks the connection.
Why it's wrong here
By default, the firewall does not block connections solely because the server certificate is untrusted. It uses the forward untrust certificate to re-sign the connection, which may cause a client warning but not necessarily a block. The access issue is more likely due to client-side trust of the firewall's certificate. Thus, this is not the most likely cause.
- ✗
The website requires TLS 1.3, which the firewall cannot decrypt.
Why it's wrong here
Palo Alto Networks firewalls can decrypt TLS 1.3 with proper configuration, such as enabling TLS 1.3 decryption in the decryption profile. While there can be compatibility issues, it is not the most likely cause for a self-signed certificate site. The access issue is more directly related to certificate trust on the client side.
- ✗
The decryption policy rule is misconfigured to not decrypt the website.
Why it's wrong here
If the decryption policy rule does not decrypt the website, the traffic would pass through without decryption, and the client would connect directly to the website. The self-signed certificate would then cause a warning from the website itself, but the scenario states that decryption was enabled, so the rule is likely decrypting. The issue is more about the firewall's certificate being trusted.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.