Courseiva
Decryption and MonitoringhardMultiple ChoiceObjective-mapped

PCNSA Decryption and Monitoring Practice Question

A large enterprise uses Palo Alto Networks firewalls with SSL Forward Proxy to inspect all HTTPS traffic (port 443) from internal users. Recently, users have reported slow web browsing and intermittent failures when accessing certain financial and healthcare websites. The firewall's dataplane CPU consistently reaches 85-95% during business hours. The decryption policy is configured with a single rule that decrypts all outbound HTTPS traffic using the default SSL Forward Proxy settings. The firewall is a PA-5250 with ample license capacity. What should the administrator do to resolve the performance issues while maintaining security posture?

⚠ Common exam trap

Watch out — candidates often assume hardware acceleration (Option D) is a magic fix for all performance issues, but in reality, the PA-5250 already has it enabled, and the bottleneck is the CPU's capacity to handle the cryptographic operations, not the acceleration feature itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement decryption exclusion rules for financial and healthcare websites.

Financial and healthcare websites often use certificate pinning or require specific cipher suites that may not be compatible with the firewall's default SSL Forward Proxy settings. By excluding these sites from decryption, the administrator reduces the decryption load on the dataplane CPU and avoids breaking connectivity to sensitive sites, while still decrypting the majority of HTTPS traffic to maintain security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase the maximum number of concurrent SSL sessions allowed.

    Why it's wrong here

    This would not reduce CPU usage; it might exacerbate the issue.

  • Disable decryption for high-bandwidth websites such as video streaming services.

    Why it's wrong here

    This would reduce inspection for popular services, potentially missing threats.

  • Implement decryption exclusion rules for financial and healthcare websites.

    Why this is correct

    Excluding problematic sites reduces decryption overhead while maintaining security on most traffic.

  • Enable hardware acceleration for SSL decryption.

    Why it's wrong here

    The PA-5250 already uses hardware acceleration; this would not solve the CPU issue.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.