Courseiva

PCNSE · topic practice

Decryption and SSL Inspection practice questions

This domain covers how the firewall decrypts, inspects, and re-encrypts TLS traffic using SSL Forward Proxy, SSL Inbound Inspection, and SSH Proxy, plus how to exempt traffic from decryption. Questions present configuration exhibits, decryption policy rules, and bypassed-session logs, asking you to identify causes and select correct settings.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Decryption and SSL Inspection

What the exam tests

What to know about Decryption and SSL Inspection

Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.

Configuring SSL Forward Proxy and SSL Inbound Inspection decryption policies with trusted certificates

Using no-decrypt rules, decryption exclusions, and certificate trust to handle pinned or sensitive traffic

Reading decryption logs and session details to diagnose bypassed, decrypted, or errored sessions

Understanding certificate management, forward trust/forward untrust CAs, and certificate revocation checking

Watch out for

Common Decryption and SSL Inspection exam traps

  • ▸Assuming all HTTPS traffic is decrypted by default; decryption requires explicit decryption policy rules and a forward trust certificate.
  • ▸Forgetting that no-decrypt rules and exclusions must be ordered correctly, since first-match policy evaluation determines decryption.
  • ▸Overlooking that pinned applications, certificate errors, or untrusted issuers cause sessions to bypass decryption rather than fail.

Practice set

Decryption and SSL Inspection questions

20 questions · select your answer, then reveal the explanation

Which THREE statements are true regarding SSL Forward Proxy decryption on Palo Alto Networks firewalls?

Question 2hardmultiple choice
Read the full MPLS explanation →

You are a network security engineer at a multinational corporation. The company has a main data center and three branch offices connected via MPLS. The firewall at the data center is a PA-5250 running PAN-OS 10.2. The firewall is configured for SSL Forward Proxy decryption of all outbound HTTPS traffic from internal users to the internet. Recently, users in Branch Office A report that they cannot access several external HTTPS websites, while users at other branches and the data center have no issues. The decryption policy for Branch Office A is identical to the others. You check the decryption statistics and see that for Branch Office A, the number of 'SSL handshake failures' is high. You also notice that the firewall's system log shows errors like 'peer certificate chain validation failure' for sessions from Branch Office A. The firewall has a forward trust certificate issued by an internal CA, and the internal CA certificate is installed on all clients. What is the most likely cause of this issue?

Match each high availability (HA) term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

One firewall handles traffic; the other stands by

Both firewalls handle traffic simultaneously

Keepalive messages exchanged between HA peers

Original active firewall reclaims role after recovery

Firewall that initially processed a session

After enabling SSL Forward Proxy decryption, users report that they cannot access HTTPS websites and receive certificate errors. The firewall's decryption certificate is properly installed on client machines. What is the most likely cause?

An organization is deploying SSL inbound proxy decryption (SSLi) to protect servers in a DMZ. Which consideration is critical for the firewall to properly decrypt inbound traffic destined to these servers?

A company wants to decrypt traffic to productivity and collaboration sites but avoid decrypting traffic to financial and healthcare sites due to compliance. How should the SSL decryption policy be configured?

Which best practice should be followed for certificate management when deploying SSL Forward Proxy decryption in a large enterprise?

A Palo Alto Networks firewall is configured for SSL Forward Proxy decryption. The security team wants to ensure that decrypted traffic is also inspected by an external DLP appliance. How should this be achieved?

Which TWO conditions typically cause the firewall to bypass SSL decryption for a session? (Choose two.)

Which TWO types of traffic should typically be excluded from SSL decryption for compliance or operational reasons? (Choose two.)

Question 11hardmultiple choice
Review the full subnetting walkthrough →

A user from subnet 10.0.1.0/24 accesses a website categorized as 'Finance'. Based on the exhibit, what will be the result?

Exhibit

Refer to the exhibit.
```
Decryption Policy Rule 1:
  Name: Decrypt_HR_Traffic
  Source: 10.0.1.0/24
  Destination: any
  Service: any
  URL Category: Human-Resources
  Action: decrypt

Decryption Policy Rule 2:
  Name: Decrypt_All
  Source: any
  Destination: any
  Service: any
  URL Category: any
  Action: decrypt

Decryption Policy Rule 3:
  Name: No_Decrypt_Finance
  Source: any
  Destination: any
  Service: any
  URL Category: Finance
  Action: no-decrypt

Ordering: Rule 1, Rule 2, Rule 3
```

Based on the exhibit, what is the most likely action for the firewall to take on this session?

Exhibit

Refer to the exhibit.
```
2019-03-21 10:15:33.456 ssl_decrypt: session 12345, error: ssl_decrypt_cert_verify_failed, reason: certificate has expired
```

A company uses SSL Forward Proxy decryption for user traffic. Recently, some users cannot access a specific HTTPS website that uses a self-signed certificate. The firewall's decryption policy is set to 'decrypt' and the action is 'forward proxy'. The firewall does not have the self-signed CA certificate installed. What is the most likely cause of the issue?

Which TWO statements are true about TLS version 1.3 support in Palo Alto Networks decryption?

A network administrator is troubleshooting decryption failures for HTTPS traffic to a financial website. The firewall is configured with SSL Forward Proxy decryption policy that applies to the 'financial-services' URL category. The firewall uses an internal CA certificate to sign generated certificates. Users report a certificate error in their browsers when accessing 'https://www.bankofalice.com'. The error says the certificate is not trusted, even though the internal CA certificate is installed on all client devices. The administrator checks the firewall logs and sees no decryption errors; the session is being decrypted successfully. The administrator also confirms that the decryption policy is active and the firewall is not bypassing decryption. What is the most likely cause of the certificate error?

A company has deployed SSL Inbound Inspection to inspect HTTPS traffic to their internal web server hosting a custom application that requires mutual TLS authentication. The firewall is configured with a decryption policy that includes the server's certificate and the action 'decrypt'. The web server is configured to request client certificates. After implementation, users report that the application fails to authenticate them. The firewall logs show that SSL handshake with the client completes successfully, but the server never receives the client certificate during the handshake. The administrator has verified that the decryption policy is active and the server certificate is correctly imported. What is the most likely cause of this issue?

A network administrator observes that some SSL connections are failing to be decrypted. Based on the exhibit, what is the most likely reason for the majority of the failures?

Exhibit

Refer to the exhibit.

admin@PA-5000> show decryption statistics

Total Decrypted Packets: 12345
Total SSL Handshake Attempts: 1000
Successful Handshakes: 950
Failed Handshakes: 50
  - Decryption policy not matched: 20
  - Certificate validation failure: 15
  - Unsupported cipher: 10
  - Other: 5

A security engineer at a financial services company is implementing SSL Forward Proxy decryption on a Palo Alto Networks firewall to inspect outbound HTTPS traffic. The company has strict compliance requirements and wants to avoid decrypting traffic to banking and healthcare websites. The engineer needs to configure the firewall to bypass decryption for these sites while still decrypting all other HTTPS traffic. Which TWO actions should the engineer take to achieve this goal? (Choose two.)

An engineer is configuring SSL Forward Proxy decryption on a PA-5220 firewall running PAN-OS 11.1. The firewall must decrypt outbound HTTPS traffic for all users except those in the Finance department, who must be exempt from decryption. The engineer creates a Decryption policy rule with a source user group 'Finance' and action 'no-decrypt'. However, after committing, Finance users report that their HTTPS traffic is still being decrypted. What is the most likely reason?

A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. Users report that after enabling decryption, they receive certificate errors when accessing HTTPS websites. The administrator has already installed the forward trust certificate on the firewall and deployed the forward trust CA certificate to all user workstations via Group Policy. What is the most likely cause of the certificate errors?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Decryption and SSL Inspection sessions

Start a Decryption and SSL Inspection only practice session

Every question in these sessions is drawn from the Decryption and SSL Inspection domain — nothing else.

Related practice questions

Related PCNSE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSE exam test about Decryption and SSL Inspection?
Be able to build and order decryption policy rules, attach the correct forward trust and forward untrust certificates, and read logs to explain why sessions are decrypted, bypassed, or blocked. The single most important thing is correct first-match rule ordering with proper no-decrypt exclusions.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Decryption and SSL Inspection questions in a focused session?
Yes — the session launcher on this page draws every question from the Decryption and SSL Inspection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSE topics?
Use the topic links above to move to related areas, or go back to the PCNSE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSE exam covers. They are not copied from any real exam or dump site.