Key Design Considerations for SSL Forward Proxy Decryption
Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?
Quick Answer
The answer is that the firewall uses a decryption policy to determine which traffic to decrypt, and it dynamically generates a session-specific certificate signed by a trusted CA to re-encrypt traffic to the client. This is correct because in an SSL forward proxy design, the Palo Alto firewall acts as a man-in-the-middle, terminating the client’s TLS connection, inspecting the decrypted payload, and then initiating a new TLS connection to the server. To avoid certificate warnings, the firewall must generate a certificate on the fly for each session, signed by a CA certificate that is pre-installed and trusted on client devices. On the PCNSE exam, this concept tests your understanding of how decryption policies control traffic selection and how certificate handling ensures seamless inspection without breaking client trust. A common trap is confusing forward proxy with inbound inspection, where the server’s original certificate is used. Memory tip: think “policy picks, proxy signs” — the decryption policy decides what to decrypt, and the firewall signs a new cert for each session.
⚠ Common exam trap
It's easy for candidates to assume SSL Forward Proxy can decrypt all TLS traffic, including sessions with client certificate authentication, but the firewall cannot possess the client's private key and thus must skip decryption for such sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.
Option C is correct because SSL Forward Proxy works by having the firewall act as a man-in-the-middle: it intercepts the client's TLS session, presents a certificate it generates (signed by a Forward Trust certificate) for the requested server, and then establishes a separate TLS session to the actual server, so a certificate must be generated for each decrypted session to re-encrypt traffic to the client. Option E is correct because decryption in Palo Alto Networks firewalls is governed by a Decryption policy, which lets administrators selectively define which traffic (by source, destination, user, URL category, service, etc.) is decrypted, forwarded, or excluded from decryption. Option A is incorrect because decryption is not global; the Decryption policy enables granular, selective decryption and exclusions. Option B is incorrect because SSL Forward Proxy cannot decrypt sessions that use client certificate authentication (mutual TLS), since the firewall cannot present the client's private key. Option D is incorrect because SNI is not a requirement that forces decryption; traffic with SNI can pass through undecrypted, and the firewall does not drop it merely for using SNI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Decryption is applied globally to all traffic; selective decryption is not possible.
Why it's wrong here
SSL Forward Proxy supports decryption policies that selectively decrypt, bypass or block traffic by URL category, user or source. Assuming global-only decryption is tempting because a base decryption policy applies broadly, yet granular rules let organisations exclude sensitive categories such as finance and health.
- ✗
The firewall can decrypt all TLS sessions regardless of client certificate authentication.
Why it's wrong here
Client certificate authentication breaks forward proxy decryption: the firewall cannot present the client's certificate to the server, so mutually authenticated sessions fail or must be excluded. Assuming universal decryption is tempting because the proxy terminates TLS, but sessions requiring client certificates are typically bypassed.
- ✓
When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.
Why this is correct
SSL Forward Proxy requires the firewall to present a forged certificate to the client, signed by a trusted Forward Trust CA, so it can decrypt and inspect traffic before re-encrypting. This per-session certificate generation is intrinsic to the proxy mechanism, satisfying the design consideration that the firewall impersonates the destination server for every decrypted session.
- ✗
Traffic using Server Name Indication (SNI) in TLS must be decrypted at the firewall or it will be dropped.
Why it's wrong here
SNI is carried in the unencrypted ClientHello, so the firewall reads it without decryption; no drop occurs. It is tempting because SNI-based decryption rules and ESNI/ECH handling do involve SNI, but that governs policy matching, not a decryption-or-drop requirement.
- ✓
The firewall uses a decryption policy to determine which traffic to decrypt.
Why this is correct
A decryption policy governs SSL Forward Proxy by matching traffic against defined rules, so only sessions meeting your criteria are intercepted and decrypted. This directly satisfies the design consideration of selective decryption, letting you exclude sensitive categories such as finance or healthcare, and so balance inspection coverage against privacy, performance and legal compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PCNSE
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE statements are true regarding SSL Forward Proxy decryption on Palo Alto Networks firewalls?
hard- A.SSL Forward Proxy decryption can only be applied to traffic destined for TCP port 443.
- ✓ B.Decryption policy rules can match on source zone, source user, destination IP, URL category, and service.
- ✓ C.The firewall must generate a certificate on-the-fly signed by a trusted CA for each decrypted session.
- D.An 'ssl-decrypt' action in a decryption rule requires that the associated decryption profile includes a certificate for the firewall to use.
- ✓ E.The firewall can inspect the Server Name Indication (SNI) field in the ClientHello to determine the destination hostname.
Why B: Palo Alto Networks decryption policy rules can match on a wide range of criteria including source zone, source user, destination IP, URL category, and service. This granularity allows administrators to selectively decrypt traffic based on business needs and security policies, not just basic IP/port matching.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.