PCNSA Decryption and Monitoring Practice Question
A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?
⚠ Common exam trap
PCNSA often tests the confusion between user-based and IP-based policies, especially in decryption contexts where candidates might think source IP is sufficient, but the question explicitly mentions user identity, so source user is the correct match.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Source user
Source user is correct because decryption policies based on user identity require matching the user information obtained from Active Directory integration. The firewall uses User-ID to map IP addresses to usernames, and the decryption policy can then enforce rules based on the source user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Source user
Why this is correct
Source user matches decryption policy rules against the username resolved from Active Directory via User-ID, so policies apply per identity rather than by IP address or application. This satisfies the requirement to base decryption on user identity.
- ✗
URL category
Why it's wrong here
URL category classifies the destination website, not the requesting user, so decryption cannot be tied to identity. Category matching suits decrypting traffic to risky site groups such as newly registered domains, irrespective of which authenticated user initiates the session.
- ✗
Source zone
Why it's wrong here
Source zone identifies the ingress interface, not the authenticated user, so decryption rules cannot match on identity. Zone-based criteria suit topology-driven policy, such as decrypting traffic entering from an untrusted external zone regardless of who the user is.
- ✗
Source IP address
Why it's wrong here
Source IP address matches a network location, not a directory user, so identity-based decryption cannot be enforced; DHCP and roaming break the mapping. IP criteria suit static server-to-server decryption, where the peer address reliably identifies the endpoint rather than a person.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.