PCNSA Decryption and Monitoring Practice Question
An administrator must ensure that outbound SSL decryption is applied to user web traffic while excluding banking and healthcare sites that break under inspection. The administrator wants the firewall to skip decryption for these sensitive categories without disabling decryption globally. What should the administrator configure in the decryption policy?
⚠ Common exam trap
Many candidates confuse decryption policy with security policy or URL filtering, when only a decryption policy no-decrypt rule can exclude traffic from inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A decryption policy rule with action 'no-decrypt' and a URL Category match for the sensitive categories
Decryption policy rules determine which sessions are decrypted or bypassed, and they can match on URL Category. To exclude sensitive categories while decrypting other web traffic, the administrator should create a no-decrypt rule for those categories and place it above the general decrypt rule. Security policy, decryption profiles, and URL filtering profiles do not control whether a session is decrypted, so they cannot satisfy the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A decryption policy rule with action 'no-decrypt' and a URL Category match for the sensitive categories
Why this is correct
Decryption policy rules support actions such as decrypt and no-decrypt, and they can match on URL Category. Placing a no-decrypt rule above the general decrypt rule for the sensitive categories ensures those sites bypass inspection while all other web traffic is still decrypted. This meets the requirement without disabling decryption globally and preserves inspection for the remaining traffic.
- ✗
A decryption profile with 'Block Untrusted Issuers' enabled for the sensitive categories
Why it's wrong here
Decryption profiles define how the firewall handles certificates, protocols, and unsupported cipher suites during decryption. They do not select which traffic is decrypted or bypassed. Enabling Block Untrusted Issuers would cause more sessions to fail, not exclude the sensitive categories from decryption. Traffic selection is controlled by decryption policy rules, not by the decryption profile attached to them.
- ✗
A security policy rule with action 'allow' and application 'ssl' for the sensitive categories
Why it's wrong here
Security policy controls whether traffic is permitted or denied, not whether it is decrypted. Allowing SSL for specific categories does not exclude them from a decryption policy that matches all web traffic. To skip decryption, the administrator must use a decryption policy rule with the no-decrypt action, not a security policy rule, because decryption decisions are made separately from security enforcement.
- ✗
A URL Filtering profile with action 'alert' for the sensitive categories
Why it's wrong here
URL Filtering profiles determine whether access to categories is allowed, blocked, or alerted, but they do not control decryption. Even if the profile alerts on banking or healthcare categories, the decryption policy would still decrypt those sessions unless a no-decrypt rule exists. URL filtering operates after decryption decisions, so it cannot prevent decryption of the specified categories.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.