PCNSA Decryption and Monitoring Practice Question
A network security administrator is configuring SSL Forward Proxy decryption on a Palo Alto Networks firewall. The administrator wants to exclude employee access to healthcare portals from decryption to comply with privacy regulations, while still decrypting all other HTTPS traffic. Which decryption policy configuration should the administrator use?
⚠ Common exam trap
Test-takers frequently confuse decryption policy with security policy or URL filtering, assuming that a security rule or URL filter can control decryption behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a decryption policy rule with action 'no-decrypt' for the healthcare portal URLs, placed above the general decrypt rule.
Decryption policies are separate from security policies and are evaluated top-down. A no-decrypt rule for specific URLs, placed above a general decrypt rule, allows the administrator to exclude healthcare portals from decryption while decrypting all other HTTPS traffic. This satisfies privacy compliance without blocking access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a decryption policy rule with action 'no-decrypt' for the healthcare portal URLs, placed above the general decrypt rule.
Why this is correct
This is correct because decryption policies are evaluated top-down, and a no-decrypt rule for specific URLs ensures those sessions bypass decryption while all other HTTPS traffic is decrypted by the subsequent rule. This meets the privacy requirement without affecting general inspection.
- ✗
Configure a URL Filtering profile to block the healthcare portals, preventing any access.
Why it's wrong here
Blocking access does not satisfy the requirement to allow access without decryption. URL Filtering controls access, not decryption behavior. The administrator needs to permit the traffic but exclude it from decryption, which is achieved through decryption policy, not URL filtering.
- ✗
Add the healthcare portal IP addresses to the SSL Decryption Exclusion list under Device > Setup > Session.
Why it's wrong here
The SSL Decryption Exclusion list is for client-side exclusions based on server certificate attributes, not for URL-based exclusions. It is typically used for applications that break when decrypted. Using it here would not reliably exclude specific URLs and lacks the granularity of a decryption policy rule.
- ✗
Create a security policy rule with action 'allow' and attach a decryption profile that disables decryption for those URLs.
Why it's wrong here
Decryption profiles define how to handle decrypted traffic (e.g., certificate checks), not whether to decrypt. They cannot selectively disable decryption for specific URLs. The correct approach is a decryption policy rule with no-decrypt action, not a security policy rule with a decryption profile.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.