PCNSE Decryption and SSL Inspection Practice Question
A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?
⚠ Common exam trap
It's easy for candidates to confuse certificate pinning with general certificate validation or assume that any decryption policy misconfiguration (like URL filtering) is the cause, rather than recognizing the specific application-level security mechanism that explicitly rejects the firewall's decryption certificate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The application uses certificate pinning which rejects the firewall's decryption certificate.
Certificate pinning is a security mechanism where an application embeds the exact certificate or public key of the server it expects to communicate with. When SSL decryption is enabled, the firewall replaces the original server certificate with its own decryption certificate. The application detects this mismatch and rejects the connection, causing it to fail to load completely. This is a common issue with applications that implement strict certificate pinning, such as banking apps or certain mobile applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The URL is not allowed in the decryption policy.
Why it's wrong here
A URL excluded from decryption is bypassed, not blocked, so the session still loads. Decryption exemptions exist to preserve pinned or legally protected traffic, and would be correct where policy must skip inspection rather than cause partial page failure.
- ✗
The user's browser proxy settings are incorrect.
Why it's wrong here
Browser proxy settings affect whether traffic reaches the proxy, not whether decrypted sessions complete; the failure stems from decryption breaking certificate pinning or unsupported ciphers. It is tempting because proxy misconfiguration does cause load failures, and it would be correct if the issue appeared independently of enabling SSL decryption.
- ✓
The application uses certificate pinning which rejects the firewall's decryption certificate.
Why this is correct
Certificate pinning hard-codes the expected server certificate or public key within the application, so the firewall's re-signed certificate fails validation and the connection is dropped. This directly explains the partial loading described, where pinned resources break while unpinned content still loads after SSL decryption is enabled.
- ✗
The firewall's decryption is causing excessive latency.
Why it's wrong here
Latency degrades throughput but does not selectively break application loading; decryption failures stem from certificate pinning or unsupported cipher suites, not delay. Latency matters when sizing IPS or shaping bandwidth, where added inspection overhead is the actual concern.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.