PCNSA Decryption and Monitoring Practice Question
Which THREE of the following are valid actions for a decryption policy rule? (Choose three.)
⚠ Common exam trap
Palo Alto Networks often tests the distinction between decryption policy actions and security policy actions, so the trap here is confusing 'Block' (a security rule action) with decryption rule actions, or assuming 'Forward' is a decryption action when it is actually a default behavior for non-decrypted traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No Decrypt
In a Palo Alto Networks decryption policy, the three valid rule actions are No Decrypt, Forward Untrust Certificate, and Decrypt. Option A (No Decrypt) is correct because it allows specified traffic to bypass decryption entirely, which is used for traffic that cannot or should not be decrypted, such as pinned or sensitive sessions. Option B (Forward Untrust Certificate) is correct because it is a specific decryption action that presents the firewall's untrust certificate to clients when the destination server certificate is not trusted, enabling continued inspection. Option E (Decrypt) is correct because it is the primary action that instructs the firewall to decrypt and inspect matching SSL/TLS traffic. Options C (Block) and D (Forward) are not valid decryption policy actions; Block is a security policy action, and Forward is not a decryption rule action in this context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
No Decrypt
Why this is correct
No Decrypt leaves matching traffic encrypted, so the firewall forwards it without inspection. This satisfies the scenario's requirement to exempt traffic that cannot legally be decrypted, such as financial or healthcare sessions, while still enforcing the decryption policy rule's action set alongside Decrypt and No Decrypt with decryption profile options.
- ✓
Forward Untrust Certificate
Why this is correct
Forward Untrust Certificate is a valid decryption policy action: it presents an untrusted certificate to the client, prompting a browser warning, rather than decrypting traffic. This satisfies the scenario's requirement for a rule action that blocks or warns on sessions without performing decryption, alongside No Decrypt and Decrypt options.
- ✗
Block
Why it's wrong here
Block belongs to security policy rules, not decryption policy rules, which only decrypt, no-decrypt or bypass traffic. It is tempting because blocking malicious sessions is a core firewall function, and a decryption rule can indirectly expose threats that security policy then blocks.
- ✗
Forward
Why it's wrong here
Forward is not a decryption policy action; the three valid actions are decrypt, no-decrypt and bypass. It is tempting because forwarding describes traffic handling elsewhere in PAN-OS, such as a forwarding profile or log forwarding, where it genuinely applies.
- ✓
Decrypt
Why this is correct
Decrypt is a valid action within a decryption policy rule, instructing the firewall to terminate the session's encryption and inspect the plaintext payload. The other rule actions are no-decrypt and bypass, so this satisfies the question's requirement.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.