Courseiva

PCNSE Decryption and SSL Inspection Practice Question

Which THREE steps should be taken to troubleshoot an SSL decryption issue where users are unable to access specific HTTPS websites? (Choose three.)

⚠ Common exam trap

Many candidates confuse decryption failures with URL filtering or policy issues, leading them to select option B, when in fact decryption logs and certificate trust are the direct troubleshooting steps for SSL decryption problems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the decryption log for errors such as 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed'.

Option A is correct because the decryption log is the primary place to identify the exact failure reason, and messages like 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed' directly point to cipher mismatch or certificate validation problems breaking the HTTPS session. Option C is correct because SSL decryption requires the firewall to present its own certificate to the client; if that forward-trust or decryption certificate is not trusted by the client, the TLS handshake fails and the site becomes inaccessible. Option E is correct because a packet capture of the SSL handshake across client, firewall, and server reveals where the handshake breaks, such as a failed ClientHello, certificate alert, or SNI mismatch, which is essential for isolating the fault. Option B does not belong because URL filtering database categorization affects policy enforcement, not the cryptographic SSL decryption process. Option D does not belong because disabling decryption globally is a disruptive workaround, not a troubleshooting step, and it would not identify the root cause of the decryption failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the decryption log for errors such as 'ssl_decrypt_unsupported_cipher' or 'ssl_decrypt_cert_verify_failed'.

    Why this is correct

    The decryption log records the precise failure reason for each session, exposing whether the firewall rejected the server certificate chain or hit an unsupported cipher during the handshake. This directly satisfies the stem's need to identify why specific HTTPS sites fail, since the logged error code names the exact stage that broke.

  • ✗

    Update the URL filtering database to ensure the site is categorized correctly.

    Why it's wrong here

    URL filtering categories govern permit or block decisions, not whether the firewall can complete a TLS handshake, so a mis-categorised site would be blocked outright rather than failing decryption. It is tempting because category lookups appear in the same policy path, and it would be correct when legitimate sites are blocked due to incorrect URL database categorisation.

  • ✓

    Verify that the firewall's decryption certificate is trusted by the client.

    Why this is correct

    Client browsers silently drop TLS connections when the forward-trust certificate chain presented by the firewall is not anchored in their trust store, producing exactly the "specific HTTPS websites" failure described. Verifying the decryption certificate is trusted by the client confirms the firewall can re-sign server traffic without triggering certificate-validation errors.

  • ✗

    Disable decryption globally to see if the sites become accessible.

    Why it's wrong here

    Disabling decryption globally removes the policy that could be breaking these sessions, but it also removes visibility and enforcement for all traffic, so it cannot isolate the faulty rule. It is tempting as a quick isolation test, and it would be correct when confirming whether decryption itself causes a widespread outage before narrowing to specific policies.

  • ✓

    Use the packet capture tool to analyze the SSL handshake between client, firewall, and server.

    Why this is correct

    Packet capture exposes the actual TLS handshake, revealing whether the firewall's forward proxy or the server rejects the ClientHello, and which cipher or certificate causes failure. This satisfies the stem's need to isolate where decryption breaks across client, firewall and server, confirming the specific failing stage rather than guessing at policy.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.