Courseiva
Decryption and Monitoring →mediumMultiple Choice

PCNSA Decryption and Monitoring Practice Question

A company wants to ensure that decryption policies are applied based on the user identity. The firewall is integrated with Active Directory. Which decryption policy matching criteria should be used?

⚠ Common exam trap

PCNSA often tests the confusion between user-based and IP-based policies, especially in decryption contexts where candidates might think source IP is sufficient, but the question explicitly mentions user identity, so source user is the correct match.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Source user

Source user is correct because decryption policies based on user identity require matching the user information obtained from Active Directory integration. The firewall uses User-ID to map IP addresses to usernames, and the decryption policy can then enforce rules based on the source user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Source user

    Why this is correct

    Source user matches decryption policy rules against the username resolved from Active Directory via User-ID, so policies apply per identity rather than by IP address or application. This satisfies the requirement to base decryption on user identity.

  • ✗

    URL category

    Why it's wrong here

    URL category classifies the destination website, not the requesting user, so decryption cannot be tied to identity. Category matching suits decrypting traffic to risky site groups such as newly registered domains, irrespective of which authenticated user initiates the session.

  • ✗

    Source zone

    Why it's wrong here

    Source zone identifies the ingress interface, not the authenticated user, so decryption rules cannot match on identity. Zone-based criteria suit topology-driven policy, such as decrypting traffic entering from an untrusted external zone regardless of who the user is.

  • ✗

    Source IP address

    Why it's wrong here

    Source IP address matches a network location, not a directory user, so identity-based decryption cannot be enforced; DHCP and roaming break the mapping. IP criteria suit static server-to-server decryption, where the peer address reliably identifies the endpoint rather than a person.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.