Courseiva

PCNSE · domain

Decryption and SSL Inspection

This domain covers how the firewall decrypts, inspects, and re-encrypts TLS traffic using SSL Forward Proxy, SSL Inbound Inspection, and SSH Proxy, plus how to exempt traffic from decryption. Questions present configuration exhibits, decryption policy rules, and bypassed-session logs, asking you to identify causes and select correct settings.

22 questions7 easy7 medium8 hard

Focused practice

Practice Decryption and SSL Inspection questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Decryption and SSL Inspection

Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.

Configuring SSL Forward Proxy and SSL Inbound Inspection decryption policies with trusted certificates

Using no-decrypt rules, decryption exclusions, and certificate trust to handle pinned or sensitive traffic

Reading decryption logs and session details to diagnose bypassed, decrypted, or errored sessions

Understanding certificate management, forward trust/forward untrust CAs, and certificate revocation checking

Watch out for

Common Decryption and SSL Inspection exam traps

  • ▸Assuming all HTTPS traffic is decrypted by default; decryption requires explicit decryption policy rules and a forward trust certificate.
  • ▸Forgetting that no-decrypt rules and exclusions must be ordered correctly, since first-match policy evaluation determines decryption.
  • ▸Overlooking that pinned applications, certificate errors, or untrusted issuers cause sessions to bypass decryption rather than fail.

Question index

All Decryption and SSL Inspection questions (22)

Click any question to see the full explanation, or start a practice session above.

1

A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?

Medium
2

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt outbound HTTPS traffic and present a valid certificate to internal users. Which certificate must be installed on the firewall to sign the certificates presented to internal users during SSL Forward Proxy decryption?

Easy
3

A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?

Hard
4

Which TWO of the following are supported decryption scenarios on a Palo Alto Networks firewall?

Easy
5

A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?

Easy
6

Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?

Hard
7

A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?

Easy
8

A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?

Medium
9

During SSL decryption, the firewall logs show 'ssl_decrypt_unsupported_cipher' errors for several connections. What is the likely cause and solution?

Hard
10

An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?

Medium
11

A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?

Hard
12

A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?

Easy
13

What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?

Easy
14

Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)

Hard
15

A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?

Medium
16

A network security engineer is troubleshooting an SSL decryption issue. Users report that after decryption was enabled, they cannot access certain HTTPS websites that use certificate pinning. The firewall is configured with SSL Forward Proxy decryption. Which action should the engineer take to allow access to these websites while still decrypting other traffic?

Hard
17

A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?

Hard
18

Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?

Medium
19

A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?

Easy
20

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?

Medium
21

Order the steps to configure a static route on a Palo Alto Networks firewall.

Medium
22

A security administrator has configured SSL decryption on a Palo Alto Networks firewall. After decryption, some users report that they cannot access a specific banking website, and the firewall logs show the session as 'decryption excluded' for that site. The administrator wants to ensure that the firewall does not decrypt traffic to this banking site while still decrypting all other HTTPS traffic. What should the administrator configure to achieve this?

Hard

Frequently asked questions

What does the Decryption and SSL Inspection domain cover on the PCNSE exam?
Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.
How many questions are in this domain?
This page lists all 22 Decryption and SSL Inspection questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Decryption and SSL Inspection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
paloalto-pcnse PALOALTO-PCNSE decryption ssl Practice Questions