Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks NGFW-Engineer Exam - Topic 2 Question 26 Discussion

An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving "Your connection is not private" browser errors for all external websites.What is the most likely cause of these widespread certificate errors?
D) The firewall's self-signed CA certificate is not deployed to the trusted certificate store on client endpoints.
A) The decryption policy is configured with a 'no-decrypt' action, which causes browsers to reject the connection.
B) The external websites are using TLS 1.3, which cannot be decrypted by the firewall without a specific license.
C) The firewall's forward untrust certificate has expired, preventing it from identifying untrusted sites.

Palo Alto Networks NGFW-Engineer Exam - Topic 2 Question 26 Discussion

Actual exam question for Palo Alto Networks's NGFW-Engineer exam
Question #: 26
Topic #: 2
[All NGFW-Engineer Questions]

An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving "Your connection is not private" browser errors for all external websites.

What is the most likely cause of these widespread certificate errors?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Tish
3 days ago
I agree, D is the most likely cause here.
upvoted 0 times
...
Latrice
8 days ago
No way, it can't be just the self-signed cert, right?
upvoted 0 times
...
Belen
13 days ago
I thought TLS 1.3 was the issue at first, but it’s probably just the cert.
upvoted 0 times
...
Thaddeus
19 days ago
Definitely D! Users need that cert in their trusted store.
upvoted 0 times
...
Susana
24 days ago
Sounds like a classic case of missing the self-signed cert on client devices.
upvoted 0 times
...
Antonio
29 days ago
I recall that for SSL Forward Proxy to work properly, the self-signed CA certificate needs to be installed on client devices. That might be the problem here.
upvoted 0 times
...
Janine
1 month ago
I think it could be related to the forward untrust certificate being expired, but I’m not confident about that.
upvoted 0 times
...
Annelle
1 month ago
I'm not entirely sure, but I feel like the "no-decrypt" action could be causing the browsers to reject the connection. It sounds familiar from practice questions.
upvoted 0 times
...
Veronika
1 month ago
I remember studying about SSL decryption, and I think the issue might be related to the self-signed certificate not being trusted by the clients.
upvoted 0 times
...

Save Cancel