Courseiva

PCNSE Decryption and SSL Inspection Practice Question

A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?

⚠ Common exam trap

The trap here is assuming that the forward untrust certificate should be used to resolve client trust warnings, when actually the forward trust certificate's issuing CA must be trusted by the client.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Import the internal certificate authority's root certificate into the users' browsers' trusted root store.

The browser warning occurs because the firewall re-signs the partner site's certificate with its forward trust certificate, which is issued by the company's internal CA. If the client does not trust that CA, validation fails. Importing the internal CA root into the users' browsers' trusted root store establishes trust, allowing decryption to continue without warnings. The other options either bypass decryption or misuse certificate types, failing to resolve the trust issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the partner site to the SSL Decryption Exclusion list.

    Why it's wrong here

    Adding the partner site to the exclusion list would bypass decryption for that site, eliminating the certificate warning but also defeating the purpose of inspecting that traffic. The scenario requires maintaining decryption, so excluding the site is not appropriate. The root cause is client trust of the forward trust certificate, not the partner site's certificate.

  • ✗

    Install the forward untrust certificate on the firewall and present it to the partner site.

    Why it's wrong here

    The forward untrust certificate is used when the destination server's certificate cannot be validated; presenting it to the partner site is not the purpose. In this scenario, the partner site's certificate is likely valid but the client does not trust the firewall's forward trust certificate, so using the untrust certificate would not resolve the browser warning and could worsen trust issues.

  • ✗

    Configure the firewall to use the forward trust certificate as the forward untrust certificate.

    Why it's wrong here

    The forward trust and forward untrust certificates serve different purposes. The forward trust certificate is used for sites the firewall trusts; the forward untrust certificate is used when the destination certificate is untrusted. Using the trust certificate as untrust does not address the client's lack of trust in the issuing CA and may cause further validation failures.

  • ✓

    Import the internal certificate authority's root certificate into the users' browsers' trusted root store.

    Why this is correct

    For SSL Forward Proxy decryption, the firewall presents a certificate signed by its forward trust certificate. If the client does not trust the issuing CA, it will show a warning. Importing the internal CA root into the users' trusted root store allows the browser to validate the re-signed certificate, resolving the warning while keeping decryption active.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.