Exam NGFW-Engineer Topic 1 Question 102 Discussion
Actual exam question for Palo Alto Networks's NGFW-Engineer exam
Question #: 102
Topic #: 1
Question #: 102
Topic #: 1
An administrator enables SSL Forward Proxy decryption using a self-signed certificate on a Palo Alto Networks firewall as the forward trust certificate. Shortly after, users report receiving "Your connection is not private" browser errors for all external websites.
What is the most likely cause of these widespread certificate errors?
What is the most likely cause of these widespread certificate errors?
Suggested Answer: D Vote an answer
SSL Forward Proxy relies on the firewall acting as a trusted certificate authority. If the self-signed forward trust certificate is not installed in the trusted root certificate store of client devices, browsers will not trust the certificates generated by the firewall, resulting in widespread
"connection not private" warnings for all decrypted HTTPS sites.
"connection not private" warnings for all decrypted HTTPS sites.
by Vito at Sep 29, 2026, 11:11 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).