PCNSE URL Category-based decryption Practice Question
A company wants to decrypt traffic to productivity and collaboration sites but avoid decrypting traffic to financial and healthcare sites due to compliance. How should the SSL decryption policy be configured?
⚠ Common exam trap
The trap is assuming a decrypt-all rule with exceptions provides acceptable compliance. In reality, the decrypt-all action still decrypts all traffic momentarily, which may breach compliance requirements for protected categories.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a rule to decrypt based on URL categories except financial and healthcare.
Palo Alto Networks' SSL decryption policy can use URL categories to specify which traffic to decrypt. Creating a rule that decrypts traffic based on URL categories except for financial and healthcare ensures compliance by never decrypting those sensitive categories. Option A is wrong because maintaining a custom URL list is inefficient and prone to errors compared to using built-in categories. Option B is wrong because a decrypt-all rule with exceptions would initially decrypt all traffic, including financial and healthcare, before the exception is applied, which could violate compliance. Option D is wrong because decryption policy does not support time-based rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add all financial and healthcare sites to a custom URL list and exclude them.
Why it's wrong here
Impractical to list all sites; categories are dynamic.
- ✗
Create a decrypt-all rule and then add exceptions for financial and healthcare categories.
Why it's wrong here
Not efficient; exceptions could miss other compliance issues.
- ✓
Create a rule to decrypt based on URL categories except financial and healthcare.
Why this is correct
Allows targeted decryption based on categories.
- ✗
Use time-based rules to apply decryption only during business hours.
Why it's wrong here
Time-based rules are not applicable for category-based exclusions.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 504-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.