Courseiva

PCNSE Decryption and SSL Inspection Practice Question

A multinational corporation uses Palo Alto Networks firewalls at its headquarters and five branch offices. SSL Forward Proxy decryption is enabled for all outbound HTTPS traffic. Recently, users in the finance department have reported that several banking and financial websites fail to load, displaying a certificate error in the browser. The errors occur only for these specific sites, while other HTTPS sites work fine. The firewall administrator has already added decryption exclusion rules for the affected domains, but the problem persists. The decryption policy is configured with a single rule that decrypts all ssl service traffic, and the exclusion rules are placed below this global decrypt rule. Which of the following is the best course of action to resolve the issue?

⚠ Common exam trap

Test-takers frequently confuse decryption profiles with decryption policy rules, thinking a profile can exclude domains, when in fact domain exclusion is strictly a function of rule ordering in the decryption policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reorder the decryption policy rules so that the exclusion rules are above the global decrypt rule

Palo Alto Networks decryption policy rules are evaluated in top-down order, and the first matching rule is applied. Since the exclusion rules are placed below the global decrypt rule that decrypts all SSL traffic, the global rule matches first and decrypts the traffic, causing certificate errors on sites that require specific handling. Reordering the exclusion rules above the global rule ensures they are evaluated first, allowing the affected domains to bypass decryption and load correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a decryption profile that excludes the failing domains

    Why it's wrong here

    Decryption profiles govern cipher, protocol and certificate-checking behaviour, not which traffic bypasses decryption. Exclusion is a policy action, so the profile cannot stop the failing sites being decrypted. Profiles would be correct when tuning session settings for traffic already being decrypted.

  • ✗

    Disable SSL decryption for all traffic

    Why it's wrong here

    Disabling decryption globally removes inspection for every site, not just the failing banking domains, and abandons the security requirement. It would be the fallback if decryption were entirely unsupportable, but the exclusion rules simply sit below the catch-all decrypt rule and are never evaluated.

  • ✓

    Reorder the decryption policy rules so that the exclusion rules are above the global decrypt rule

    Why this is correct

    Decryption policy rules are evaluated top-down, so the global decrypt rule above the exclusions matches first and decrypts the banking traffic anyway. Moving the exclusion rules above it lets those domains bypass SSL Forward Proxy, resolving the certificate errors caused by pinned or untrusted certificates.

  • ✗

    Replace the firewall's internal CA certificate with a publicly trusted certificate

    Why it's wrong here

    The firewall's forward-trust certificate is presented to internal clients, so replacing it with a publicly trusted certificate does not stop the firewall re-signing bank sites, and public CAs will not issue for those domains. This would suit inbound SSL decryption, not forward proxy.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.