hardMultiple Choice
PCNSA Practice Question: Is planning to deploy SSL decryption for outbound…
An organization is planning to deploy SSL decryption for outbound traffic. They want to inspect all traffic from internal users to the internet, but they need to exclude traffic to financial sites for compliance reasons. Which approach should be taken?
⚠ Common exam trap
PCNSA often tests the order of decryption rules; candidates may forget that the no-decrypt rule must be placed above the decrypt rule to take effect, or they may confuse application filters with URL categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a decryption policy with a custom URL category that includes financial sites and set the action to 'no-decrypt', then place it above the general decrypt rule.
Creating a decryption policy with a custom URL category for financial sites and setting the action to 'no-decrypt' (C) allows granular control to exclude specific traffic from SSL inspection while decrypting all other outbound traffic. Placing this rule above the general decrypt rule ensures it is evaluated first, so financial sites bypass decryption. This meets the compliance requirement without disabling decryption globally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable SSL decryption for all traffic.
Why it's wrong here
Disabling decryption entirely removes inspection of all outbound traffic, contradicting the requirement to inspect everything except financial sites. It tempts as a simple compliance shortcut, but the correct approach is a decryption policy with a URL category exception, preserving inspection elsewhere.
- ✗
Configure a decryption exception on the firewall system settings.
Why it's wrong here
System settings exceptions apply globally and cannot target the financial-site category required for compliance scoping. It tempts because system-level exceptions do exist for decryption, but the correct approach uses a decryption policy rule with a URL category exception, matching traffic selectively.
- ✓
Create a decryption policy with a custom URL category that includes financial sites and set the action to 'no-decrypt', then place it above the general decrypt rule.
Why this is correct
This is the correct approach. By creating a decryption policy with a custom URL category for financial sites and setting action to 'no-decrypt', the traffic to those sites is excluded from decryption. Placing it above the general decrypt rule ensures it matches first.
- ✗
Use an application filter to exclude financial apps from decryption.
Why it's wrong here
Using an application filter is not reliable because financial traffic may use various applications and protocols that are not easily captured by application filters. Additionally, decryption policies operate on URL categories and not application filters for decryption decisions.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.