PCNSE Decryption and SSL Inspection Practice Question
A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?
⚠ Common exam trap
Many exam-takers confuse SSL Inbound Inspection with SSL Forward Proxy decryption, leading to the selection of forward trust or untrust certificates instead of the server's own certificate and private key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The internal web server's certificate and private key
For SSL Inbound Inspection, the firewall must have the internal web server's certificate and private key. This allows the firewall to decrypt the inbound SSL traffic, inspect it, and then re-encrypt it to the server. The forward trust and untrust certificates are used for forward proxy decryption, not inbound inspection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A self-signed certificate generated by the firewall
Why it's wrong here
A self-signed certificate generated by the firewall is not used for inbound inspection. Inbound inspection requires the actual server certificate and private key so that the firewall can decrypt and re-encrypt the traffic transparently. A self-signed certificate would cause certificate errors for clients unless they trust it, but it would not enable decryption of traffic to the internal server.
- ✗
Forward untrust certificate
Why it's wrong here
The forward untrust certificate is used in forward proxy decryption when the server's certificate cannot be verified. It is not used for inbound inspection. Inbound inspection requires the internal server's certificate and private key to decrypt traffic destined to that server.
- ✗
Forward trust certificate
Why it's wrong here
The forward trust certificate is used for SSL Forward Proxy decryption of outbound traffic, not inbound inspection. For inbound inspection, the firewall needs the private key of the internal server's certificate to decrypt the traffic. The forward trust certificate is not used in this scenario.
- ✓
The internal web server's certificate and private key
Why this is correct
For SSL Inbound Inspection, the firewall must have the internal server's certificate and its private key to decrypt the traffic. The firewall acts as the server to the client, decrypting the session, inspecting it, and then re-encrypting it to the server. This requires the server's private key to be imported into the firewall.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.