Courseiva
Policy Evaluation and ManagementmediumMultiple ChoiceObjective-mapped

PCNSA Policy Evaluation and Management Practice Question

Exhibit

Refer to the exhibit.

admin@PA-3060> show running security-policy
Total rules: 1
    1:  Name: Allow-Outbound, Zone: trust->untrust, Source: 10.0.0.0/24, Dest: any, Application: any, Service: any, Action: allow

A user from 10.0.0.5 tries to access 8.8.8.8 on TCP 443. The traffic is matched to the above rule. Which additional configuration is required for the traffic to be decrypted?

⚠ Common exam trap

Many exam-takers assume a Decryption policy rule alone is enough to decrypt traffic, overlooking that a Decryption Profile must be attached to define the decryption method (e.g., SSL Forward Proxy) and handle certificate validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Both a Decryption policy rule and a Decryption Profile

For traffic to be decrypted, a Decryption policy rule must explicitly match the traffic and a Decryption Profile with SSL Forward Proxy enabled must be applied. The rule alone only identifies traffic for potential decryption; the profile defines the decryption method (e.g., SSL Forward Proxy) and controls certificate handling. Without both, the firewall will not perform decryption even if the security rule allows the traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A Decryption policy rule matching the same traffic

    Why it's wrong here

    A rule alone is insufficient; a profile must also be configured.

  • An SSL Forward Proxy certificate installed

    Why it's wrong here

    The certificate is part of the decryption profile, not a standalone requirement.

  • Both a Decryption policy rule and a Decryption Profile

    Why this is correct

    Both are necessary to match and execute decryption.

  • A Decryption Profile with SSL Forward Proxy enabled

    Why it's wrong here

    A profile alone cannot be applied without a decryption policy rule.

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.