Courseiva
Decryption and SSL InspectionhardMultiple SelectObjective-mapped

Key Design Considerations for SSL Forward Proxy Decryption

Which TWO of the following are valid considerations when designing an SSL Forward Proxy decryption deployment in a Palo Alto Networks firewall?

Quick Answer

The answer is that the firewall uses a decryption policy to determine which traffic to decrypt, and it dynamically generates a session-specific certificate signed by a trusted CA to re-encrypt traffic to the client. This is correct because in an SSL forward proxy design, the Palo Alto firewall acts as a man-in-the-middle, terminating the client’s TLS connection, inspecting the decrypted payload, and then initiating a new TLS connection to the server. To avoid certificate warnings, the firewall must generate a certificate on the fly for each session, signed by a CA certificate that is pre-installed and trusted on client devices. On the PCNSE exam, this concept tests your understanding of how decryption policies control traffic selection and how certificate handling ensures seamless inspection without breaking client trust. A common trap is confusing forward proxy with inbound inspection, where the server’s original certificate is used. Memory tip: think “policy picks, proxy signs” — the decryption policy decides what to decrypt, and the firewall signs a new cert for each session.

⚠ Common exam trap

It's easy for candidates to assume SSL Forward Proxy can decrypt all TLS traffic, including sessions with client certificate authentication, but the firewall cannot possess the client's private key and thus must skip decryption for such sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.

In an SSL Forward Proxy deployment, the firewall acts as a man-in-the-middle: it terminates the client's TLS connection, inspects the decrypted traffic, and then initiates a new TLS connection to the server. To re-encrypt the traffic back to the client, the firewall must dynamically generate a certificate for each session, signed by a trusted CA certificate installed on the client devices. This ensures the client sees a valid certificate chain and does not generate a certificate warning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Decryption is applied globally to all traffic; selective decryption is not possible.

    Why it's wrong here

    Decryption policy allows selective decryption based on multiple criteria.

  • The firewall can decrypt all TLS sessions regardless of client certificate authentication.

    Why it's wrong here

    Sessions with client certificate authentication cannot be decrypted unless the client certificate is imported on the firewall.

  • When deploying SSL Forward Proxy, the firewall must generate a certificate for each decrypted session to re-encrypt traffic to the client.

    Why this is correct

    The firewall acts as a proxy, generating a certificate signed by a trusted CA to re-encrypt traffic to the client.

  • Traffic using Server Name Indication (SNI) in TLS must be decrypted at the firewall or it will be dropped.

    Why it's wrong here

    SNI is used for routing but not required for decryption; traffic without SNI can still be decrypted.

  • The firewall uses a decryption policy to determine which traffic to decrypt.

    Why this is correct

    Decryption policy rules define which traffic is decrypted based on source, destination, URL category, etc.

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PCNSE

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE statements are true regarding SSL Forward Proxy decryption on Palo Alto Networks firewalls?

hard
  • A.SSL Forward Proxy decryption can only be applied to traffic destined for TCP port 443.
  • B.Decryption policy rules can match on source zone, source user, destination IP, URL category, and service.
  • C.The firewall must generate a certificate on-the-fly signed by a trusted CA for each decrypted session.
  • D.An 'ssl-decrypt' action in a decryption rule requires that the associated decryption profile includes a certificate for the firewall to use.
  • E.The firewall can inspect the Server Name Indication (SNI) field in the ClientHello to determine the destination hostname.

Why B: Palo Alto Networks decryption policy rules can match on a wide range of criteria including source zone, source user, destination IP, URL category, and service. This granularity allows administrators to selectively decrypt traffic based on business needs and security policies, not just basic IP/port matching.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.