nerdexam
Palo_Alto_Networks

PCNSE · Question #840

Review the screenshots. What is the most likely reason for this decryption error log?

The correct answer is B. The client expected a certificate from a different CA than the one provided. The error "Received fatal alert UnknownCA from Client" indicates that the client did not recognize or trust the CA certificate presented by the firewall during the decryption process. This typically happens when the client is configured to expect a certificate signed by a…

Submitted by wei.xz· Apr 18, 2026Configuration Troubleshooting

Question

Review the screenshots. What is the most likely reason for this decryption error log?

Exhibit

PCNSE question #840 exhibit

Options

  • AThe Certificate fingerprint could not be found.
  • BThe client expected a certificate from a different CA than the one provided.
  • CThe client received a CA certificate that has expired or is not valid.
  • DEntrust is not a trusted root certificate authority (CA).

How the community answered

(38 responses)
  • A
    3% (1)
  • B
    82% (31)
  • C
    11% (4)
  • D
    5% (2)

Explanation

The error "Received fatal alert UnknownCA from Client" indicates that the client did not recognize or trust the CA certificate presented by the firewall during the decryption process. This typically happens when the client is configured to expect a certificate signed by a different CA or the provided CA certificate does not align with the client's trust settings. The firewall's presented certificate likely does not match the client's expected CA, which caused the connection to fail.

Topics

#SSL Decryption#Certificate Authorities (CA)#TLS/SSL Handshake#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice