nerdexam
Palo_Alto_Networks

PCNSE · Question #173

An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?

The correct answer is A. Security policy rule allowing SSL to the target server. Inbound decryption is where you are decrypting traffic to your internal server. You don't use a Root CA, you load that server's cert and private key. The Root cert is 'Optional'. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-inbound-

Submitted by hans_de· Apr 18, 2026Configuration Troubleshooting

Question

An administrator encountered problems with inbound decryption. Which option should the administrator investigate as part of triage?

Options

  • ASecurity policy rule allowing SSL to the target server
  • BFirewall connectivity to a CRL
  • CRoot certificate imported into the firewall with "Trust" enabled
  • DImportation of a certificate from an HSM

How the community answered

(22 responses)
  • A
    82% (18)
  • B
    9% (2)
  • C
    5% (1)
  • D
    5% (1)

Explanation

Inbound decryption is where you are decrypting traffic to your internal server. You don't use a Root CA, you load that server's cert and private key. The Root cert is 'Optional'. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/configure-ssl-inbound-

Topics

#SSL Decryption#Security Policy#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice