nerdexam
Palo_Alto_Networks

PCNSE · Question #507

An organization wishes to roll out decryption but gets some resistance from engineering leadership regarding the guest network. What is a common obstacle for decrypting traffic from guest devices?

The correct answer is D. Guest devices may not trust the CA certificate used for the forward trust certificate. When SSL/TLS decryption is enabled, the firewall acts as a man-in-the-middle and re-signs server certificates using its own CA. The 'forward trust' certificate is used when the firewall trusts the server's certificate (the common case for legitimate HTTPS sites). For decryption…

Submitted by deeparc· Apr 18, 2026Plan

Question

An organization wishes to roll out decryption but gets some resistance from engineering leadership regarding the guest network. What is a common obstacle for decrypting traffic from guest devices?

Options

  • AGuest devices may not trust the CA certificate used for the forward untrust certificate.
  • BGuests may use operating systems that can't be decrypted.
  • CThe organization has no legal authority to decrypt their traffic.
  • DGuest devices may not trust the CA certificate used for the forward trust certificate.

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    9% (3)
  • C
    3% (1)
  • D
    82% (28)

Explanation

When SSL/TLS decryption is enabled, the firewall acts as a man-in-the-middle and re-signs server certificates using its own CA. The 'forward trust' certificate is used when the firewall trusts the server's certificate (the common case for legitimate HTTPS sites). For decryption to work transparently, client devices must have the organization's forward trust CA certificate installed in their trusted root store. Corporate devices are managed and can have this CA pushed via GPO or MDM, but guest devices are unmanaged - they will not trust the organization's CA and will receive certificate errors for every HTTPS site they visit. This makes SSL decryption impractical on guest networks. Answer A is wrong because the 'forward untrust' certificate applies only when the server's own certificate is untrusted, which is the less common scenario.

Topics

#SSL Decryption#Guest Network#Certificate Trust#Forward Trust

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice