PCNSE Decryption and SSL Inspection Practice Question
A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?
⚠ Common exam trap
Test-takers frequently confuse decryption profiles with decryption policy rules, thinking a profile can exclude domains, when in fact domain exclusion is strictly a function of rule ordering in the decryption policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reorder the decryption policy rules so that the exclusion rules are above the global decrypt rule
Palo Alto Networks decryption policy rules are evaluated in top-down order, and the first matching rule is applied. Since the exclusion rules are placed below the global decrypt rule that decrypts all SSL traffic, the global rule matches first and decrypts the traffic, causing certificate errors on sites that require specific handling. Reordering the exclusion rules above the global rule ensures they are evaluated first, allowing the affected domains to bypass decryption and load correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a decryption profile that excludes the failing domains
Why it's wrong here
Decryption profiles govern cipher, protocol and certificate-checking behaviour, not which traffic bypasses decryption. Exclusion is a policy action, so the profile cannot stop the failing sites being decrypted. Profiles would be correct when tuning session settings for traffic already being decrypted.
- ✗
Disable SSL decryption for all traffic
Why it's wrong here
Disabling decryption globally removes inspection for every site, not just the failing banking domains, and abandons the security requirement. It would be the fallback if decryption were entirely unsupportable, but the exclusion rules simply sit below the catch-all decrypt rule and are never evaluated.
- ✓
Reorder the decryption policy rules so that the exclusion rules are above the global decrypt rule
Why this is correct
Decryption policy rules are evaluated top-down, so the global decrypt rule above the exclusions matches first and decrypts the banking traffic anyway. Moving the exclusion rules above it lets those domains bypass SSL Forward Proxy, resolving the certificate errors caused by pinned or untrusted certificates.
- ✗
Replace the firewall's internal CA certificate with a publicly trusted certificate
Why it's wrong here
The firewall's forward-trust certificate is presented to internal clients, so replacing it with a publicly trusted certificate does not stop the firewall re-signing bank sites, and public CAs will not issue for those domains. This would suit inbound SSL decryption, not forward proxy.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.