PCNSE · domain
Decryption and SSL Inspection
This domain covers how the firewall decrypts, inspects, and re-encrypts TLS traffic using SSL Forward Proxy, SSL Inbound Inspection, and SSH Proxy, plus how to exempt traffic from decryption. Questions present configuration exhibits, decryption policy rules, and bypassed-session logs, asking you to identify causes and select correct settings.
Focused practice
Practice Decryption and SSL Inspection questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Decryption and SSL Inspection
Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.
Configuring SSL Forward Proxy and SSL Inbound Inspection decryption policies with trusted certificates
Using no-decrypt rules, decryption exclusions, and certificate trust to handle pinned or sensitive traffic
Reading decryption logs and session details to diagnose bypassed, decrypted, or errored sessions
Understanding certificate management, forward trust/forward untrust CAs, and certificate revocation checking
Watch out for
Common Decryption and SSL Inspection exam traps
- ▸Assuming all HTTPS traffic is decrypted by default; decryption requires explicit decryption policy rules and a forward trust certificate.
- ▸Forgetting that no-decrypt rules and exclusions must be ordered correctly, since first-match policy evaluation determines decryption.
- ▸Overlooking that pinned applications, certificate errors, or untrusted issuers cause sessions to bypass decryption rather than fail.
Question index
All Decryption and SSL Inspection questions (22)
Click any question to see the full explanation, or start a practice session above.
A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?
Medium2A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt outbound HTTPS traffic and present a valid certificate to internal users. Which certificate must be installed on the firewall to sign the certificates presented to internal users during SSL Forward Proxy decryption?
Easy3A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?
Hard4Which TWO of the following are supported decryption scenarios on a Palo Alto Networks firewall?
Easy5A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?
Easy6Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?
Hard7A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?
Easy8A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?
Medium9During SSL decryption, the firewall logs show 'ssl_decrypt_unsupported_cipher' errors for several connections. What is the likely cause and solution?
Hard10An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?
Medium11A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?
Hard12A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?
Easy13What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?
Easy14Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)
Hard15A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?
Medium16A network security engineer is troubleshooting an SSL decryption issue. Users report that after decryption was enabled, they cannot access certain HTTPS websites that use certificate pinning. The firewall is configured with SSL Forward Proxy decryption. Which action should the engineer take to allow access to these websites while still decrypting other traffic?
Hard17A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?
Hard18Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?
Medium19A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?
Easy20A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?
Medium21Order the steps to configure a static route on a Palo Alto Networks firewall.
Medium22A security administrator has configured SSL decryption on a Palo Alto Networks firewall. After decryption, some users report that they cannot access a specific banking website, and the firewall logs show the session as 'decryption excluded' for that site. The administrator wants to ensure that the firewall does not decrypt traffic to this banking site while still decrypting all other HTTPS traffic. What should the administrator configure to achieve this?
HardOther domains
All PCNSE exam domains
Frequently asked questions
- What does the Decryption and SSL Inspection domain cover on the PCNSE exam?
- Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.
- How many questions are in this domain?
- This page lists all 22 Decryption and SSL Inspection questions in the PCNSE question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Decryption and SSL Inspection questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.