Courseiva

PCNSE Decryption and SSL Inspection Practice Question

A network security administrator is configuring SSL decryption on a Palo Alto Networks firewall. The administrator wants to ensure that traffic to a specific banking website is never decrypted due to privacy concerns. Which configuration object should be used to achieve this?

⚠ Common exam trap

A common mix-up: candidates confuse the SSL Decryption Exclusion list with decryption policy rules; the exclusion list is specifically for excluding sites by domain without creating a policy rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSL Decryption Exclusion list with the specific domain of the banking website.

The SSL Decryption Exclusion list is designed to bypass decryption for specific domains based on the server certificate's CN or SAN. Adding the banking website's domain ensures that traffic to that site is not decrypted, addressing privacy concerns without affecting other traffic. Other options either apply too broadly, block traffic incorrectly, or do not provide selective exclusion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SSL Decryption Exclusion list with the specific domain of the banking website.

    Why this is correct

    The SSL Decryption Exclusion list allows administrators to specify domains that should never be decrypted, based on the server certificate's CN or SAN. Adding the specific banking website's domain ensures that traffic to that site bypasses decryption, addressing privacy concerns. This is the most granular method for excluding individual sites without affecting others.

  • ✗

    SSL Forward Proxy setting with 'Strip TLS 1.3' enabled.

    Why it's wrong here

    Stripping TLS 1.3 is used to handle incompatibilities or to enforce downgrade for decryption, but it does not exclude specific sites. Enabling this would affect all TLS 1.3 sessions and could cause connectivity issues. It does not provide a way to selectively bypass decryption for a particular banking website.

  • ✗

    Decryption profile with 'Block sessions with untrusted issuers' enabled.

    Why it's wrong here

    A decryption profile with that setting blocks sessions when the server certificate is untrusted, but it does not exclude specific sites from decryption. It would actually cause the firewall to block the banking site if its certificate is untrusted, which is not the desired outcome. The requirement is to bypass decryption, not to block based on trust.

  • ✗

    Decryption policy rule with action 'no-decrypt' and a URL category of 'financial-services'.

    Why it's wrong here

    A decryption policy rule with action 'no-decrypt' can bypass decryption, but using a URL category of 'financial-services' would exclude all financial sites, not just the specific banking website. The requirement is to exclude only one specific site, so a more granular approach is needed. This option is too broad and may unintentionally bypass decryption for other financial sites.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.