nerdexam
Palo_Alto_Networks

PCNSE · Question #580

An engineer needs to configure SSL Forward Proxy to decrypt traffic on a PA-5260. The engineer uses a forward trust certificate from the enterprise PKI that expires December 31, 2025. The validity…

The correct answer is B. The server certificate. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8wCAC "The validity date on the Palo Alto Networks firewall generated certificate is taken from the validity date on the real server certificate."

Submitted by carter_n· Apr 18, 2026Deploy and Configure

Question

An engineer needs to configure SSL Forward Proxy to decrypt traffic on a PA-5260. The engineer uses a forward trust certificate from the enterprise PKI that expires December 31, 2025. The validity date on the PA-generated certificate is taken from what?

Options

  • AThe trusted certificate
  • BThe server certificate
  • CThe untrusted certificate
  • DThe root CA

How the community answered

(34 responses)
  • A
    6% (2)
  • B
    91% (31)
  • D
    3% (1)

Explanation

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8wCAC "The validity date on the Palo Alto Networks firewall generated certificate is taken from the validity date on the real server certificate."

Topics

#SSL Forward Proxy#Certificate Validity#SSL Decryption#PA-Series Firewalls

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice