Courseiva

PCNSA Decryption and Monitoring Practice Question

A Palo Alto Networks firewall is configured with SSL Forward Proxy decryption for outbound traffic. The administrator notices that some sessions to a banking website are being decrypted even though the organization's policy requires that financial sites be excluded from decryption. The decryption policy rule for financial URL categories is set to 'no-decrypt'. Which action should the administrator take to ensure these sessions are not decrypted?

⚠ Common exam trap

The trap here is assuming that adding a no-decrypt rule anywhere in the policy is sufficient, when rule order determines which action takes effect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the no-decrypt rule above the decrypt rule in the decryption policy rulebase and verify that the URL category is correctly matched.

Decryption policy rules are order-dependent, and the first match wins. If a decrypt rule precedes the no-decrypt rule, financial sites can be decrypted despite the no-decrypt rule's presence. Moving the no-decrypt rule above the decrypt rule and verifying the URL category match ensures financial traffic is correctly excluded from decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the forward untrust certificate for the banking site so the firewall does not decrypt it.

    Why it's wrong here

    The forward untrust certificate is used when the firewall decrypts a site that fails trust validation, causing clients to see a warning. It does not prevent decryption. Assigning the forward untrust certificate to the banking site would still result in decryption and likely break access, rather than honoring the no-decrypt policy.

  • ✗

    Disable SSL Forward Proxy globally and rely on SSL Inbound Inspection for outbound traffic.

    Why it's wrong here

    SSL Inbound Inspection is designed for traffic destined to internal servers, not outbound client traffic. Disabling SSL Forward Proxy globally would stop all outbound decryption, which is broader than the required exclusion for financial sites. This action does not selectively exclude the banking website and disrupts the overall decryption strategy.

  • ✗

    Add the banking website's IP addresses to the SSL Exclude list in the decryption profile.

    Why it's wrong here

    The SSL Exclude list in a decryption profile is not used to exclude destinations from decryption; decryption exclusions are controlled by decryption policy rules. The decryption profile governs behaviors like blocking unsupported ciphers or untrusted certificates. Using it to exclude IP addresses would not achieve the desired no-decrypt action for the banking site.

  • ✓

    Place the no-decrypt rule above the decrypt rule in the decryption policy rulebase and verify that the URL category is correctly matched.

    Why this is correct

    Decryption policy rules are evaluated top-down, and the first matching rule determines the action. If a decrypt rule appears above the no-decrypt rule, financial sites may be decrypted before the no-decrypt rule is evaluated. Moving the no-decrypt rule to the top and confirming the URL category match ensures financial traffic is excluded as intended.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.