Courseiva
Decryption and Monitoring →mediumMultiple Choice

PCNSA Decryption and Monitoring Practice Question

Exhibit

> show decryption rule
rule name: Default-No-Decrypt, source: any, dest: any, action: no-decrypt
rule name: Decrypt-Web, source: any, dest: any, action: decrypt, profile: strict

Refer to the exhibit. A decryption policy has two rules. Traffic destined to a web server is not being decrypted. What is the most likely cause?

⚠ Common exam trap

Palo Alto Networks often tests the concept of rule order in decryption policies, where candidates mistakenly focus on profile settings or source/destination fields instead of recognizing that a higher-priority 'no-decrypt' rule matching all traffic will override any lower-priority decrypt rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Default-No-Decrypt rule is above Decrypt-Web and matches all traffic

In Palo Alto Networks firewalls, decryption policy rules are evaluated in order from top to bottom, and the first matching rule is applied. If the 'Default-No-Decrypt' rule is placed above the 'Decrypt-Web' rule and matches all traffic (e.g., source/destination 'any'), then all traffic, including traffic to the web server, will match this rule first and will not be decrypted, preventing the 'Decrypt-Web' rule from ever being evaluated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'strict' profile is misconfigured

    Why it's wrong here

    The strict profile governs certificate validation and unsupported cipher handling, not whether the rule decrypts at all. It is tempting because profile errors surface as decryption failures, but a misconfigured profile affects how traffic is decrypted, not whether the policy rule matches and acts on it.

  • ✗

    The Decrypt-Web rule has a profile that blocks decryption

    Why it's wrong here

    A decryption profile cannot block decryption; profiles control certificate checks, unsupported protocols and cipher handling after decryption is selected. The rule's action field determines decrypt versus no-decrypt, so a no-decrypt action or a preceding match is the likely cause. Profiles are the right place to enforce session controls on traffic you have already chosen to decrypt.

  • ✓

    The Default-No-Decrypt rule is above Decrypt-Web and matches all traffic

    Why this is correct

    Rule order decides processing: Palo Alto firewalls evaluate decryption rules top-down and stop at the first match. With Default-No-Decrypt positioned above Decrypt-Web, its match-all criteria captures the web server traffic first, so the decrypt rule is never reached and no decryption occurs.

  • ✗

    The source is set to 'any' in the Decrypt-Web rule

    Why it's wrong here

    A source of any matches all traffic, which broadens rather than narrows the rule, so it cannot prevent decryption. It is tempting because overly broad match criteria look suspicious, but decryption failure stems from the rule's action or the preceding rule, not from source scope.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.