Courseiva

CCNA Decryption Ssl Questions

22 questions · Decryption Ssl topic · All types, answers revealed

1
MCQmedium

A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?

A.SSL Decryption Exclusion list with the specific domain of the banking website.
B.SSL Forward Proxy setting with 'Strip TLS 1.3' enabled.
C.Decryption profile with 'Block sessions with untrusted issuers' enabled.
D.Decryption policy rule with action 'no-decrypt' and a URL category of 'financial-services'.
AnswerA

The SSL Decryption Exclusion list allows administrators to specify domains that should never be decrypted, based on the server certificate's CN or SAN. Adding the specific banking website's domain ensures that traffic to that site bypasses decryption, addressing privacy concerns. This is the most granular method for excluding individual sites without affecting others.

Why this answer

The SSL Decryption Exclusion list is designed to bypass decryption for specific domains based on the server certificate's CN or SAN. Adding the banking website's domain ensures that traffic to that site is not decrypted, addressing privacy concerns without affecting other traffic. Other options either apply too broadly, block traffic incorrectly, or do not provide selective exclusion.

Exam trap

The trap here is confusing the SSL Decryption Exclusion list with decryption policy rules; the exclusion list is specifically for excluding sites by domain without creating a policy rule.

2
MCQeasy

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt outbound HTTPS traffic and present a valid certificate to internal users. Which certificate must be installed on the firewall to sign the certificates presented to internal users during SSL Forward Proxy decryption?

A.SSL inbound certificate
B.Forward untrust certificate
C.Forward trust certificate
D.Root CA certificate
AnswerC

The forward trust certificate is used by the firewall to sign the certificates it presents to internal clients when decrypting outbound SSL traffic. It must be a CA certificate and be trusted by the clients. This certificate enables the firewall to act as a proxy and establish separate SSL connections with the client and the server.

Why this answer

The forward trust certificate is specifically designed for SSL Forward Proxy decryption. It is a CA certificate that the firewall uses to sign the certificates presented to internal users. Clients must trust this certificate to avoid errors.

The forward untrust certificate is used for untrusted server certificates, and the SSL inbound certificate is for inbound inspection.

Exam trap

The trap here is confusing the forward trust certificate with the forward untrust certificate or the SSL inbound certificate, which serve different purposes in decryption.

3
MCQhard

A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?

A.Create a decryption profile that excludes the failing domains
B.Disable SSL decryption for all traffic
C.Reorder the decryption policy rules so that the exclusion rules are above the global decrypt rule
D.Replace the firewall's internal CA certificate with a publicly trusted certificate
AnswerC

Decryption policy rules are evaluated top-down, so the global decrypt rule above the exclusions matches first and decrypts the banking traffic anyway. Moving the exclusion rules above it lets those domains bypass SSL Forward Proxy, resolving the certificate errors caused by pinned or untrusted certificates.

Why this answer

Palo Alto Networks decryption policy rules are evaluated in top-down order, and the first matching rule is applied. Since the exclusion rules are placed below the global decrypt rule that decrypts all SSL traffic, the global rule matches first and decrypts the traffic, causing certificate errors on sites that require specific handling. Reordering the exclusion rules above the global rule ensures they are evaluated first, allowing the affected domains to bypass decryption and load correctly.

Exam trap

The trap here is that candidates often confuse decryption profiles with decryption policy rules, thinking a profile can exclude domains, when in fact domain exclusion is strictly a function of rule ordering in the decryption policy.

How to eliminate wrong answers

Option A is wrong because a decryption profile can control cipher strength or block expired certificates, but it cannot exclude domains from decryption; domain exclusion is handled by decryption policy rules, not profiles. Option B is wrong because disabling SSL decryption for all traffic would break the security inspection for all HTTPS traffic, which is an overreaction and not necessary when only a few specific sites are affected. Option D is wrong because replacing the internal CA certificate with a publicly trusted certificate would not resolve certificate errors caused by decryption of sites that pin certificates or use client certificates; the issue is policy ordering, not CA trust.

4
Multi-Selecteasy

Which TWO of the following are supported decryption scenarios on a Palo Alto Networks firewall?

Select 2 answers
A.Decryption Broker
B.SSL Forward Proxy
C.SSL Termination
D.SSH Proxy
E.SSL Inbound Inspection
AnswersB, E

Correct: SSL Forward Proxy decrypts outbound traffic from internal clients to external servers.

Why this answer

B is correct because SSL Forward Proxy allows the firewall to decrypt outbound traffic from internal clients to external servers by acting as an intermediary, generating a new certificate on the fly to inspect the session. E is correct because SSL Inbound Inspection enables the firewall to decrypt inbound traffic destined for protected servers, typically by importing the server's private key, allowing inspection of encrypted payloads.

Exam trap

The trap here is that candidates often confuse 'SSL Termination' (a load-balancer concept) with 'SSL Inbound Inspection' (a firewall decryption feature), or mistakenly think 'Decryption Broker' is a Palo Alto Networks feature when it is actually a third-party architecture.

5
MCQeasy

A security administrator notices that after enabling SSL decryption, some users cannot access a website that uses a self-signed certificate. The firewall is configured with SSL Forward Proxy decryption. What is the most likely cause of the access issue?

A.The firewall's forward trust certificate is not trusted by the client, causing a certificate warning that prevents access.
B.The website's certificate is not trusted by the firewall, so the firewall blocks the connection.
C.The website requires TLS 1.3, which the firewall cannot decrypt.
D.The decryption policy rule is misconfigured to not decrypt the website.
AnswerA

When the firewall decrypts SSL traffic, it presents a certificate signed by its forward trust certificate. If the client does not trust the issuing CA, the browser will show a certificate warning and may block access. This is a common issue when the forward trust CA is not imported into the client's trusted root store. The self-signed nature of the website's certificate may trigger the firewall to use the forward untrust certificate, but the client trust of the firewall's certificate is the critical factor.

Why this answer

The most likely cause is that the client does not trust the firewall's forward trust certificate. When SSL Forward Proxy decryption is enabled, the firewall re-signs the website's certificate with its forward trust certificate. If the client does not trust the CA that issued the forward trust certificate, it will display a warning and may block access.

This is a common oversight when deploying decryption.

Exam trap

The trap here is assuming that the self-signed certificate of the website is the direct cause, when the real issue is the client's trust of the firewall's forward trust certificate.

6
Multi-Selecthard

Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?

Select 2 answers
A.Decryption is applied globally to all traffic; selective decryption is not possible.
B.The firewall can decrypt all TLS sessions regardless of client certificate authentication.
C.When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.
D.Traffic using Server Name Indication (SNI) in TLS must be decrypted at the firewall or it will be dropped.
E.The firewall uses a decryption policy to determine which traffic to decrypt.
AnswersC, E

SSL Forward Proxy requires the firewall to present a forged certificate to the client, signed by a trusted Forward Trust CA, so it can decrypt and inspect traffic before re-encrypting. This per-session certificate generation is intrinsic to the proxy mechanism, satisfying the design consideration that the firewall impersonates the destination server for every decrypted session.

Why this answer

Option C is correct because SSL Forward Proxy works by having the firewall act as a man-in-the-middle: it intercepts the client's TLS session, presents a certificate it generates (signed by a Forward Trust certificate) for the requested server, and then establishes a separate TLS session to the actual server, so a certificate must be generated for each decrypted session to re-encrypt traffic to the client. Option E is correct because decryption in Palo Alto Networks firewalls is governed by a Decryption policy, which lets administrators selectively define which traffic (by source, destination, user, URL category, service, etc.) is decrypted, forwarded, or excluded from decryption. Option A is incorrect because decryption is not global; the Decryption policy enables granular, selective decryption and exclusions.

Option B is incorrect because SSL Forward Proxy cannot decrypt sessions that use client certificate authentication (mutual TLS), since the firewall cannot present the client's private key. Option D is incorrect because SNI is not a requirement that forces decryption; traffic with SNI can pass through undecrypted, and the firewall does not drop it merely for using SNI.

Exam trap

The trap here is that candidates often assume SSL Forward Proxy can decrypt all TLS traffic, including sessions with client certificate authentication, but the firewall cannot possess the client's private key and thus must skip decryption for such sessions.

7
MCQeasy

A security administrator wants to minimize the performance impact of SSL decryption on the firewall. Which best practice should be applied?

A.Configure decryption settings per interface to distribute load.
B.Disable SSL decryption entirely to avoid performance issues.
C.Create decryption exclusion rules for traffic that is known to be low-risk and high-volume.
D.Enable decryption on all traffic to ensure complete visibility.
AnswerC

Excluding low-risk, high-volume traffic from decryption directly reduces the CPU load on the firewall's dataplane, since each TLS session otherwise consumes processing for handshake and inspection. This satisfies the stem's constraint of minimising SSL decryption performance impact while preserving decryption for genuinely risky traffic.

Why this answer

Creating decryption exclusion rules for low-risk, high-volume traffic (e.g., software updates, video streaming, or trusted CDN traffic) reduces the firewall's decryption workload, minimizing performance impact while still allowing decryption of sensitive or risky traffic. This aligns with Palo Alto Networks best practices to balance security and performance by excluding traffic that does not require inspection.

Exam trap

The trap here is that candidates may think distributing decryption per interface (Option A) is a valid load-balancing technique, but Palo Alto Networks firewalls do not support interface-level decryption configuration, and the correct approach is to use exclusion rules to selectively bypass decryption for low-risk traffic.

How to eliminate wrong answers

Option A is wrong because decryption settings are not configured per interface to distribute load; SSL decryption is applied globally via decryption policies, and load distribution is handled by the firewall's hardware architecture, not interface-level settings. Option B is wrong because disabling SSL decryption entirely eliminates visibility into encrypted threats, which defeats the purpose of a security firewall and is not a best practice for minimizing performance impact while maintaining security. Option D is wrong because enabling decryption on all traffic would cause unnecessary performance degradation and latency, especially for high-volume, low-risk traffic that does not require inspection, violating the principle of selective decryption.

8
MCQmedium

A network security engineer is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The firewall must present a certificate to internal users for any external site they visit, signed by the company's internal certificate authority. The company's CA certificate is already imported into the firewall. Which additional configuration is required on the firewall to ensure that the Forward Trust certificate is used for signing website certificates?

A.Generate a new self-signed certificate on the firewall and assign it as the Forward Trust certificate.
B.Create a certificate signing request (CSR) for the Forward Trust certificate, have it signed by the internal CA, and import the signed certificate.
C.Assign the internal CA certificate directly as the Forward Trust certificate without generating a CSR.
D.Import the internal CA's private key and certificate into the firewall and designate it as the Forward Trust certificate.
AnswerB

This is the correct process: the firewall generates a CSR for the Forward Trust certificate, which is then signed by the internal CA. The signed certificate is imported and designated as the Forward Trust certificate. This ensures that the firewall can dynamically sign website certificates that clients trust because the internal CA is already trusted by them.

Why this answer

For SSL Forward Proxy decryption, the firewall must have a Forward Trust certificate that is trusted by internal clients. This certificate is typically a subordinate certificate signed by the organization's internal CA. The firewall generates a CSR, the CA signs it, and the resulting certificate is imported and configured as the Forward Trust certificate.

This allows the firewall to dynamically generate certificates for external sites that clients will trust.

Exam trap

The trap here is assuming that the internal CA certificate itself can be used as the Forward Trust certificate, when in fact a separate subordinate certificate must be generated and signed by the CA.

9
MCQhard

During SSL decryption, the firewall logs show 'ssl_decrypt_unsupported_cipher' errors for several connections. What is the likely cause and solution?

A.The firewall's SSL/TLS service profile does not include the cipher suites used by the client or server.
B.The firewall does not support decryption of that traffic.
C.The decryption certificate is not trusted by the client.
D.The decryption rule is not matching the traffic.
AnswerA

The error indicates a cipher suite mismatch: the negotiated algorithm is absent from the firewall's SSL/TLS service profile. Adding the required cipher suites to that profile, or aligning it with the endpoints' supported suites, resolves the failed handshakes.

Why this answer

The 'ssl_decrypt_unsupported_cipher' error indicates that the firewall's SSL/TLS proxy cannot negotiate a common cipher suite with the client or server during the decryption handshake. This occurs when the cipher suites configured in the firewall's SSL/TLS service profile do not include the ciphers offered by the client or required by the server. The solution is to update the service profile to include the necessary cipher suites, such as those based on AES-GCM or CHACHA20-POLY1305, ensuring compatibility.

Exam trap

The trap here is that candidates often confuse cipher suite mismatch with certificate trust issues or rule misconfiguration, but the specific error message 'ssl_decrypt_unsupported_cipher' directly points to the cipher suite list in the SSL/TLS service profile.

How to eliminate wrong answers

Option B is wrong because the firewall does support decryption of that traffic; the error is specifically about cipher mismatch, not a lack of decryption capability. Option C is wrong because a certificate trust issue would generate errors like 'certificate validation failed' or 'untrusted issuer', not 'unsupported cipher'. Option D is wrong because if the decryption rule were not matching, the traffic would bypass decryption entirely, and no SSL decryption error would be logged.

10
MCQmedium

An engineer is configuring SSL Forward Proxy decryption for internal users. The firewall must decrypt traffic to all external HTTPS sites except specific financial services domains that require end-to-end encryption. Which best practice should the engineer implement to achieve this?

A.Disable decryption globally and create a custom URL category for the financial domains to enable decryption only for those.
B.Create two Decryption Policy rules: one with 'ssl-decrypt' action for the general category and a second rule with 'no-decrypt' action for the financial domains.
C.Upload the server certificates for the financial domains to the firewall and enable 'no-decrypt' on the Decryption Profile.
D.Configure a single Decryption Policy rule with a 'decrypt' action and add the financial domains to the 'Exclude Certificate' list.
AnswerB

Ordering matters: the no-decrypt rule must sit above the ssl-decrypt rule, because PAN-OS evaluates decryption policy top-down and stops at the first match. This satisfies the stem's constraint that financial services domains retain end-to-end encryption while all other external HTTPS traffic is decrypted.

Why this answer

It follows the best practice of using a 'no-decrypt' rule with higher priority than the 'ssl-decrypt' rule to exclude specific traffic from decryption. This ensures that traffic to financial services domains is not decrypted, while all other external HTTPS traffic is decrypted as required.

Exam trap

The trap here is that candidates may confuse the 'Exclude Certificate' list in the Decryption Profile with a method to prevent decryption, when in fact it only affects certificate re-signing, not the decryption action itself.

How to eliminate wrong answers

Option A is wrong because disabling decryption globally and then enabling it only for specific domains would require decryption of financial traffic, which contradicts the requirement for end-to-end encryption. Option C is wrong because uploading server certificates for financial domains and enabling 'no-decrypt' on the Decryption Profile does not prevent decryption; the 'no-decrypt' action must be set in the Decryption Policy rule, not the profile. Option D is wrong because adding financial domains to the 'Exclude Certificate' list in a Decryption Profile only excludes those certificates from being re-signed, but the traffic is still decrypted, which violates the end-to-end encryption requirement.

11
MCQhard

A network engineer is troubleshooting an SSL decryption issue on a PA-5220 firewall. Users are unable to access a specific HTTPS website after SSL decryption was enabled. The engineer checks the Decryption policy and confirms that the rule for outbound HTTPS decryption is correctly configured and matched. The firewall's decryption profile is set to block sessions with untrusted issuers. The website uses a certificate signed by a public CA that is trusted by the firewall. What is the most likely cause of the access issue?

A.The firewall's decryption profile is blocking the session because the website's certificate is expired.
B.The firewall's SSL decryption license has expired, causing it to block decrypted sessions.
C.The website requires TLS 1.3, which is not supported by the firewall's decryption profile.
D.The website uses certificate pinning, causing the client to reject the firewall's forged certificate.
AnswerD

Certificate pinning in applications or browsers causes them to expect a specific certificate or public key. When the firewall performs SSL Forward Proxy decryption, it presents a forged certificate, which the client rejects if pinning is enforced. This leads to access failures. Exempting such sites from decryption is a common workaround.

Why this answer

Certificate pinning causes clients to expect a specific certificate or public key for a website. When SSL Forward Proxy decryption is enabled, the firewall presents a forged certificate, which the client rejects due to pinning. This results in access failures.

Exempting such sites from decryption is a typical solution. Other causes like expired certificates or licensing are not applicable here.

Exam trap

The trap here is assuming that a trusted public CA certificate guarantees successful decryption, overlooking client-side pinning.

12
MCQeasy

A network engineer is deploying SSL Forward Proxy decryption on a Palo Alto Networks firewall. The engineer wants to ensure that the firewall can decrypt traffic to external sites while also being able to detect if a server presents an expired certificate. Which decryption profile setting should be enabled to block sessions when the server certificate is expired?

A.Block sessions with expired certificates under SSL Forward Proxy settings.
B.Block sessions with unknown certificate status under SSL Forward Proxy settings.
C.Block sessions with untrusted issuers under SSL Forward Proxy settings.
D.Block sessions with client authentication failures under SSL Forward Proxy settings.
AnswerA

The decryption profile includes an option to block sessions when the server certificate is expired. Enabling this setting causes the firewall to drop the connection if the server's certificate has expired, preventing users from accessing potentially insecure sites. This directly addresses the requirement to block expired certificates.

Why this answer

Within a decryption profile, the SSL Forward Proxy settings include an option to block sessions when the server certificate is expired. Enabling this ensures that the firewall checks the validity period of the server's certificate and drops the connection if it has expired. This is the correct setting to meet the requirement.

Exam trap

The trap here is confusing certificate expiration with other certificate validation checks like untrusted issuer or unknown status; each has a separate setting in the decryption profile.

13
MCQeasy

What is the primary purpose of SSL decryption in a Palo Alto Networks firewall?

A.Mask the original source IP address for privacy.
B.Inspect encrypted traffic for malware, exploits, and data leakage.
C.Allow only inbound SSL traffic to be inspected.
D.Improve network performance by reducing encryption overhead.
AnswerB

SSL decryption terminates encrypted sessions so App-ID, Content-ID threat prevention, URL filtering and file blocking can examine the plaintext payload. Without it, malware, exploits and data exfiltration hidden inside TLS remain invisible to the security policy.

Why this answer

SSL decryption in a Palo Alto Networks firewall is primarily used to inspect encrypted traffic (HTTPS, SMTPS, etc.) for threats such as malware, exploits, and data leakage. Without decryption, the firewall cannot apply threat prevention, URL filtering, or data filtering policies to the encrypted payload, leaving a blind spot in security enforcement.

Exam trap

The trap here is that candidates often confuse SSL decryption with performance optimization or privacy features, but the PCNSE exam emphasizes that its core purpose is to enable visibility and inspection of encrypted traffic for threat detection.

How to eliminate wrong answers

Option A is wrong because masking the original source IP address is the function of source NAT (SNAT) or privacy features like Private IP masking, not SSL decryption. Option C is wrong because SSL decryption can inspect both inbound and outbound traffic; it is not limited to inbound SSL traffic only. Option D is wrong because SSL decryption actually adds processing overhead due to the decryption/re-encryption cycle, it does not improve network performance or reduce encryption overhead.

14
Multi-Selecthard

Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)

Select 3 answers
A.Check the decryption log for errors such as 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed'.
B.Update the URL filtering database to ensure the site is categorized correctly.
C.Verify that the firewall's decryption certificate is trusted by the client.
D.Disable decryption globally to see if the sites become accessible.
E.Use the packet capture tool to analyze the SSL handshake between client, firewall, and server.
AnswersA, C, E

The decryption log records the precise failure reason for each session, exposing whether the firewall rejected the server certificate chain or hit an unsupported cipher during the handshake. This directly satisfies the stem's need to identify why specific HTTPS sites fail, since the logged error code names the exact stage that broke.

Why this answer

Option A is correct because the decryption log is the primary place to identify the exact failure reason, and messages like 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed' directly point to cipher mismatch or certificate validation problems breaking the HTTPS session. Option C is correct because SSL decryption requires the firewall to present its own certificate to the client; if that forward-trust or decryption certificate is not trusted by the client, the TLS handshake fails and the site becomes inaccessible. Option E is correct because a packet capture of the SSL handshake across client, firewall, and server reveals where the handshake breaks, such as a failed ClientHello, certificate alert, or SNI mismatch, which is essential for isolating the fault.

Option B does not belong because URL filtering database categorization affects policy enforcement, not the cryptographic SSL decryption process. Option D does not belong because disabling decryption globally is a disruptive workaround, not a troubleshooting step, and it would not identify the root cause of the decryption failure.

Exam trap

The trap here is that candidates often confuse decryption failures with URL filtering or policy issues, leading them to select option B, when in fact decryption logs and certificate trust are the direct troubleshooting steps for SSL decryption problems.

15
MCQmedium

A company is deploying SSL Forward Proxy decryption for outbound HTTPS traffic. They want to ensure that traffic to financial sites (e.g., *.bank.com) is not decrypted due to compliance requirements. Which method should be used to exclude this traffic from decryption?

A.Configure the SSL/TLS Service Profile to bypass decryption for the domain.
B.Configure a Decryption Profile to exclude the domain.
C.Create a Decryption Policy rule matching the traffic and set the action to 'No Decrypt'.
D.Enable certificate revocation checking for the decryption zone.
AnswerC

A Decryption Policy rule with the action set to 'No Decrypt' bypasses SSL Forward Proxy decryption for traffic matching *.bank.com, satisfying the compliance constraint that financial sites remain encrypted. The firewall still permits the session, forwarding the encrypted traffic untouched, so no certificate is presented to the client and no inspection occurs.

Why this answer

In Palo Alto Networks firewalls, SSL Forward Proxy decryption is controlled by Decryption Policy rules. To exclude specific traffic from decryption, you create a Decryption Policy rule that matches the traffic (e.g., destination domain *.bank.com) and set the action to 'No Decrypt'. This ensures the firewall forwards the traffic without intercepting or decrypting it, meeting compliance requirements.

Exam trap

The trap here is confusing the purpose of Decryption Profiles (which control decryption behavior) with Decryption Policy rules (which control which traffic is decrypted), leading candidates to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because the SSL/TLS Service Profile is used to define the certificate and protocol settings for decryption, not to bypass decryption for specific domains. Option B is wrong because a Decryption Profile controls advanced decryption settings like certificate revocation checking and protocol versions, not the decision to decrypt or not. Option D is wrong because enabling certificate revocation checking for the decryption zone affects validation of certificates during decryption, not the exclusion of traffic from decryption.

16
MCQhard

A network security engineer is troubleshooting an SSL decryption issue. Users report that after decryption was enabled, they cannot access certain HTTPS websites that use certificate pinning. The firewall is configured with SSL Forward Proxy decryption. Which action should the engineer take to allow access to these websites while still decrypting other traffic?

A.Add the websites to the SSL Decryption Exclusion list.
B.Configure the firewall to use the forward untrust certificate for these websites.
C.Disable SSL decryption globally.
D.Enable 'Block sessions with untrusted issuers' in the decryption profile.
AnswerA

Certificate pinning causes applications to reject certificates that are not signed by the expected CA. When the firewall re-signs the certificate, the pinned certificate does not match, and the connection fails. Adding these websites to the SSL Decryption Exclusion list bypasses decryption for them, allowing the original certificate to be presented to the client and satisfying pinning. This resolves access issues while still decrypting other traffic.

Why this answer

Certificate pinning causes applications to reject certificates not signed by the expected CA. When the firewall decrypts and re-signs, the pinned certificate is replaced, causing failures. Adding the affected websites to the SSL Decryption Exclusion list bypasses decryption for them, allowing the original certificate to be presented and satisfying pinning.

This maintains decryption for other traffic.

Exam trap

The trap here is thinking that the forward untrust certificate or global decryption disable is the solution, when the correct approach is to exclude the specific pinned websites from decryption.

17
MCQhard

A security engineer deployed SSL Forward Proxy decryption to inspect outbound HTTPS traffic. Several users report that when they access a partner's HTTPS portal, the browser shows a certificate warning and the site fails to load. The firewall's forward trust certificate is signed by the company's internal certificate authority. Which action should the engineer take to resolve the issue while maintaining decryption?

A.Add the partner site to the SSL Decryption Exclusion list.
B.Install the forward untrust certificate on the firewall and present it to the partner site.
C.Configure the firewall to use the forward trust certificate as the forward untrust certificate.
D.Import the internal certificate authority's root certificate into the users' browsers' trusted root store.
AnswerD

For SSL Forward Proxy decryption, the firewall presents a certificate signed by its forward trust certificate. If the client does not trust the issuing CA, it will show a warning. Importing the internal CA root into the users' trusted root store allows the browser to validate the re-signed certificate, resolving the warning while keeping decryption active.

Why this answer

The browser warning occurs because the firewall re-signs the partner site's certificate with its forward trust certificate, which is issued by the company's internal CA. If the client does not trust that CA, validation fails. Importing the internal CA root into the users' browsers' trusted root store establishes trust, allowing decryption to continue without warnings.

The other options either bypass decryption or misuse certificate types, failing to resolve the trust issue.

Exam trap

The trap here is assuming that the forward untrust certificate should be used to resolve client trust warnings, when actually the forward trust certificate's issuing CA must be trusted by the client.

18
MCQmedium

Based on the exhibit, what is the most likely cause for the majority of bypassed sessions?

A.The firewall's SSL/TLS service profile does not include the cipher suites used by the clients or servers.
B.The firewall is overloaded and cannot handle more decryption sessions.
C.The decryption certificate is not trusted by clients.
D.There is a network connectivity issue between firewall and servers.
AnswerA

Bypassed sessions occur when the firewall cannot negotiate the client's or server's cipher suite, so it falls back to no decryption. If the SSL/TLS service profile lacks the required cipher suites, the handshake fails and sessions are bypassed, matching the exhibit's majority-bypass symptom.

Why this answer

The majority of bypassed sessions are most likely caused by a cipher mismatch between the firewall's SSL/TLS service profile and the clients or servers. When the firewall decrypts traffic, it must negotiate a cipher suite that both the client and server support; if the service profile does not include the cipher suites used by the endpoints, the firewall cannot complete the SSL/TLS handshake and bypasses the session. This is a common misconfiguration in Palo Alto Networks firewalls where the SSL/TLS service profile's cipher list is too restrictive.

Exam trap

The trap here is that candidates often confuse 'bypassed sessions' with 'decryption failures' due to certificate issues or network problems, but bypassed sessions specifically indicate the firewall intentionally skipped decryption due to configuration mismatches like cipher or protocol version incompatibility.

How to eliminate wrong answers

Option B is wrong because firewall overload typically results in session drops or resource exhaustion errors, not a high percentage of bypassed sessions; bypassed sessions indicate the firewall intentionally skipped decryption due to policy or configuration issues, not capacity limits. Option C is wrong because an untrusted decryption certificate causes client-side certificate warnings or connection failures, not bypassed sessions; bypassed sessions occur when the firewall cannot decrypt, not when the client rejects the certificate. Option D is wrong because a network connectivity issue between the firewall and servers would cause session timeouts or connection resets, not bypassed sessions; bypassed sessions are logged when the firewall decides not to decrypt, not when it cannot reach the server.

19
MCQeasy

A user reports that after SSL decryption was enabled, certain web applications fail to load completely. What is the most likely reason?

A.The URL is not allowed in the decryption policy.
B.The user's browser proxy settings are incorrect.
C.The application uses certificate pinning which rejects the firewall's decryption certificate.
D.The firewall's decryption is causing excessive latency.
AnswerC

Certificate pinning hard-codes the expected server certificate or public key within the application, so the firewall's re-signed certificate fails validation and the connection is dropped. This directly explains the partial loading described, where pinned resources break while unpinned content still loads after SSL decryption is enabled.

Why this answer

Certificate pinning is a security mechanism where an application embeds the exact certificate or public key of the server it expects to communicate with. When SSL decryption is enabled, the firewall replaces the original server certificate with its own decryption certificate. The application detects this mismatch and rejects the connection, causing it to fail to load completely.

This is a common issue with applications that implement strict certificate pinning, such as banking apps or certain mobile applications.

Exam trap

The trap here is that candidates often confuse certificate pinning with general certificate validation or assume that any decryption policy misconfiguration (like URL filtering) is the cause, rather than recognizing the specific application-level security mechanism that explicitly rejects the firewall's decryption certificate.

How to eliminate wrong answers

Option A is wrong because the URL being allowed or not in the decryption policy controls whether decryption is applied, but does not cause partial loading failures; if the URL is not allowed, decryption is simply not performed and the traffic passes through normally. Option B is wrong because incorrect browser proxy settings would typically cause a complete failure to reach any HTTPS sites, not selective failures with specific web applications after SSL decryption is enabled. Option D is wrong while excessive latency can degrade performance, it would not cause web applications to fail to load completely; the failure is due to certificate validation rejection, not timing out.

20
MCQmedium

A security engineer is configuring SSL decryption on a Palo Alto Networks firewall. The engineer wants to decrypt inbound SSL traffic to an internal web server for inspection. Which certificate must be installed on the firewall to perform SSL Inbound Inspection?

A.A self-signed certificate generated by the firewall
B.Forward untrust certificate
C.Forward trust certificate
D.The internal web server's certificate and private key
AnswerD

For SSL Inbound Inspection, the firewall must have the internal server's certificate and its private key to decrypt the traffic. The firewall acts as the server to the client, decrypting the session, inspecting it, and then re-encrypting it to the server. This requires the server's private key to be imported into the firewall.

Why this answer

For SSL Inbound Inspection, the firewall must have the internal web server's certificate and private key. This allows the firewall to decrypt the inbound SSL traffic, inspect it, and then re-encrypt it to the server. The forward trust and untrust certificates are used for forward proxy decryption, not inbound inspection.

Exam trap

The trap here is confusing SSL Inbound Inspection with SSL Forward Proxy decryption, leading to the selection of forward trust or untrust certificates instead of the server's own certificate and private key.

21
Drag & Dropmedium

Order the steps to configure a static route on a Palo Alto Networks firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order to configure a static route on a Palo Alto Networks firewall is: navigate to the appropriate virtual router, add a new static route entry, configure the destination address and next-hop, and then commit the configuration. This ensures the route is properly defined and applied.

22
MCQhard

A security administrator has configured SSL decryption on a Palo Alto Networks firewall. After decryption, some users report that they cannot access a specific banking website, and the firewall logs show the session as 'decryption excluded' for that site. The administrator wants to ensure that the firewall does not decrypt traffic to this banking site while still decrypting all other HTTPS traffic. What should the administrator configure to achieve this?

A.Add the banking site's certificate to the firewall's trusted certificate list and set the decryption policy to 'decrypt'.
B.Create a decryption policy rule with the action 'no-decrypt' and match the banking site's URL category or FQDN.
C.Configure a decryption profile with 'Block Untrusted Issuers' enabled and apply it to the decryption policy rule.
D.Modify the existing decryption policy rule to exclude the banking site by adding its IP address to the source field.
AnswerB

A decryption policy rule with action 'no-decrypt' allows specific traffic to bypass decryption based on criteria such as URL category, source, destination, or service. Placing this rule above the decryption rule ensures that traffic to the banking site is excluded from decryption while other HTTPS traffic is still decrypted. This is the correct method to selectively bypass decryption.

Why this answer

To exclude specific traffic from SSL decryption, a decryption policy rule with the action 'no-decrypt' must be created and placed above the decryption rule. This rule can match on various criteria such as URL category, FQDN, or source/destination. This ensures that the banking site's traffic bypasses decryption while other HTTPS traffic continues to be decrypted.

Exam trap

The trap here is confusing decryption profiles with decryption policy actions; profiles control how to handle decrypted traffic, while policy rules determine whether to decrypt or not.

Ready to test yourself?

Try a timed practice session using only Decryption Ssl questions.