PCNSA Decryption and Monitoring Practice Question
An administrator notices that the firewall is experiencing high CPU utilization due to SSL decryption. The administrator wants to reduce the load without completely disabling decryption. Which feature should be used to selectively bypass decryption for certain traffic?
⚠ Common exam trap
The trap here is thinking that hardware acceleration or decryption profiles are the primary means to reduce CPU load from decryption, when selective bypass via no-decrypt rules is the direct method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decryption policy with 'no-decrypt' action for specific URL categories.
To reduce CPU load from SSL decryption without disabling it entirely, administrators should create decryption policy rules with the 'no-decrypt' action for specific URL categories or traffic that is less critical for inspection. This selective bypass reduces the volume of decrypted sessions, lowering CPU utilization while maintaining decryption for high-risk traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a decryption profile to disable decryption for untrusted certificates.
Why it's wrong here
A decryption profile can block or allow sessions with untrusted certificates, but it does not reduce CPU load by bypassing decryption. In fact, blocking untrusted certificates may cause more overhead. The goal is to reduce load by not decrypting certain traffic, which is achieved with no-decrypt rules, not profiles.
- ✗
Enable hardware acceleration for SSL decryption.
Why it's wrong here
Hardware acceleration can improve performance but is not a selective bypass feature. It requires specific hardware and may not be available on all models. The question asks for a feature to selectively bypass decryption, not to accelerate it. Hardware acceleration is an enhancement, not a selective bypass.
- ✓
Decryption policy with 'no-decrypt' action for specific URL categories.
Why this is correct
Creating decryption policy rules with 'no-decrypt' for categories that are not critical for inspection (e.g., streaming media, social networking) reduces the volume of decrypted traffic, thereby lowering CPU load. This allows the firewall to focus resources on decrypting traffic that poses higher risk, balancing security and performance.
- ✗
SSL decryption exclusion based on source IP address.
Why it's wrong here
Excluding decryption based on source IP address is possible but not as granular or effective as using URL categories. It may bypass decryption for entire subnets, potentially missing threats. The question asks for selective bypass to reduce load, and URL category-based no-decrypt is the recommended best practice for optimizing performance.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.