exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 151 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 151
Topic #: 1
[All PCNSE Questions]

Which is not a valid reason for receiving a decrypt-cert-validation error?

  • A. Unsupported HSM
  • B. Unknown certificate status
  • C. Client authentication
  • D. Untrusted issuer
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChiaPet75
Highly Voted 4 years, 4 months ago
Correct: A The question reads, "Which is NOT a valid reason for receiving a decrypt-cert-validation error?" Per the link "hamshoo" provided, receiving the decrypt-cert-validation error is valid for the following conditions: expired, untrusted issuer, unknown status, or status verification time-out. "Unsupported HSM" is not a valid reason for receiving a decrypt-cert-validation error.
upvoted 19 times
...
swajal
Highly Voted 4 years, 4 months ago
Option 'A' Should be the answer as the question says "what is not a valid reason". HSM is not the valid reason
upvoted 9 times
...
Marshpillowz
Most Recent 9 months, 1 week ago
Selected Answer: A
Correct answer is A
upvoted 1 times
...
TAKUM1y
2 years ago
Selected Answer: A
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/troubleshoot-and-monitor-decryption/decryption-logs/decryption-log-errors-and-error-indexes
upvoted 2 times
...
yogininangpal
3 years, 5 months ago
To not to trick people they should put NOT in uppercase in the question, I am not sure what is the point of trying to ask tricky questions!
upvoted 3 times
...
PuckinWebGuy
3 years, 8 months ago
decrypt-cert-validation error would appear for SSL Forward Proxy. HSM is used to hold the private key for SSL Inbound Inspection, so an HSM issue is NOT a valid reason. Answer is A.
upvoted 5 times
...
rammsdoct
4 years, 4 months ago
@Hamshoo, yes you are right I was thinking about HSM (Hardware security module), but then read the question very carefully and it said "decrypt cert validation" which one of the options is untrusted issuer, so yes D is right!
upvoted 3 times
...
hamshoo
4 years, 4 months ago
Answer is D: https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-new-features/networking-features/ssl-ssh-session-end-reasons
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago