nerdexam
Palo_Alto_Networks

PCNSE · Question #669

An administrator is configuring SSL decryption and needs to ensure that all certificates for both SSL Inbound inspection and SSL Forward Proxy are installed properly on the firewall. When…

The correct answer is A. Forward Untrust certificate C. Forward Trust certificate D. End-entity (leaf) certificate. Private keys are required only when the firewall must actively sign or decrypt traffic. The Forward Trust certificate is used by the firewall to re-sign certificates for trusted sites during SSL Forward Proxy - it must have the private key to perform signing. The Forward…

Submitted by hassan_iq· Apr 18, 2026Deploy and Configure

Question

An administrator is configuring SSL decryption and needs to ensure that all certificates for both SSL Inbound inspection and SSL Forward Proxy are installed properly on the firewall. When certificates are being imported to the firewall for these purposes, which three certificates require a private key? (Choose three.)

Options

  • AForward Untrust certificate
  • BEnterprise Root CA certificate
  • CForward Trust certificate
  • DEnd-entity (leaf) certificate
  • EIntermediate certificate(s)

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    7% (2)
  • E
    7% (2)

Explanation

Private keys are required only when the firewall must actively sign or decrypt traffic. The Forward Trust certificate is used by the firewall to re-sign certificates for trusted sites during SSL Forward Proxy - it must have the private key to perform signing. The Forward Untrust certificate serves the same signing purpose for untrusted or unknown sites. The end-entity (leaf) certificate is required for SSL Inbound Inspection, where the firewall decrypts inbound traffic on behalf of an internal server - it needs the server's private key to do so. The Enterprise Root CA and Intermediate certificates are used only for chain-of-trust validation; the firewall only needs their public certificates, not private keys.

Topics

#SSL Decryption#Certificates#Private Key#SSL Forward Proxy

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice