Courseiva
Decryption and Monitoring →mediumMultiple Choice

PCNSA Decryption and Monitoring Practice Question

A network security administrator has configured SSL Forward Proxy decryption on a Palo Alto Networks firewall. During routine review, the administrator notices that sessions to banking websites are being decrypted, and users are receiving certificate errors. The administrator wants to stop decrypting these sessions while still decrypting all other HTTPS traffic. Which action should the administrator take?

⚠ Common exam trap

The trap here is assuming that decryption exclusions are configured in the decryption profile or exclusion list, when they are actually controlled by policy rule order.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a no-decrypt policy rule for the banking sites and place it above the decrypt rule.

Decryption policy rules are evaluated in order, and a no-decrypt rule placed above a decrypt rule will match banking traffic first, preventing decryption. The decrypt rule below continues to decrypt all other HTTPS traffic. This approach is granular, efficient, and maintains security visibility for the majority of traffic while respecting privacy or compliance requirements for financial sites.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a no-decrypt policy rule for the banking sites and place it above the decrypt rule.

    Why this is correct

    In SSL Forward Proxy, decryption policy is evaluated top-down. A no-decrypt rule matched before the decrypt rule exempts specific destinations from decryption while allowing all other HTTPS traffic to be decrypted by the subsequent decrypt rule. This is the correct way to selectively exclude traffic without disabling decryption globally.

  • ✗

    Add the banking sites to the SSL Decryption Exclusion list in the decryption profile.

    Why it's wrong here

    The SSL Decryption Exclusion list is used to exclude specific servers from decryption based on certificate attributes, but it is not the primary mechanism for creating a policy-based exception. The scenario requires a policy rule to selectively bypass decryption for these sites; the exclusion list is typically for troubleshooting or specific known incompatibilities, not for broad site categories.

  • ✗

    Change the decryption rule action from 'decrypt' to 'no-decrypt' for all traffic, then create a new rule to decrypt everything except banking.

    Why it's wrong here

    This approach would temporarily stop all decryption and then require reconfiguration, causing disruption. The correct method is to add a specific no-decrypt rule above the existing decrypt rule, preserving the decrypt rule for all other traffic. Changing the action globally is unnecessary and inefficient.

  • ✗

    Modify the decryption profile to disable decryption for the banking sites.

    Why it's wrong here

    Decryption profiles define settings such as cipher suites and certificate handling for traffic that is already being decrypted. They do not determine which traffic is decrypted; that is controlled by decryption policy rules. Disabling decryption for specific sites is not a function of the decryption profile.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.