PCNSE Manage, Monitor and Operate Practice Question
A security team is implementing SSL Decryption. They want to ensure that traffic to health-related websites is not decrypted due to privacy concerns. Which method should they use to exclude this traffic?
⚠ Common exam trap
Test-takers frequently confuse App-ID with URL filtering, thinking App-ID can selectively exclude traffic based on domain names, but App-ID operates at the application layer and cannot parse individual URLs within encrypted sessions without decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the domain names to a custom URL category and create a no-decryption rule matching that category.
Palo Alto Networks firewalls allow you to create custom URL categories containing specific domain names (e.g., health-related sites) and then reference that category in a decryption policy rule set to 'no-decrypt'. This ensures traffic matching those domains is excluded from SSL decryption, addressing privacy concerns without affecting other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a source IP address exclusion list in the decryption policy.
Why it's wrong here
Source IP exclusion exempts every flow from those addresses, so health-site traffic from other sources is still decrypted, failing the privacy requirement. It is tempting because IP lists are simple and workable, and would be correct when a known internal subnet must bypass decryption entirely, regardless of destination.
- ✗
Disable decryption for all sites that use certificate pinning.
Why it's wrong here
Certificate pinning is a client-side trust mechanism, not a URL category, so it cannot identify health-related sites for exclusion. It is tempting because pinning does break decryption, but that is handled by a decryption exclusion profile or bypass, not by disabling decryption based on pinning.
- ✓
Add the domain names to a custom URL category and create a no-decryption rule matching that category.
Why this is correct
Adding health-related domains to a custom URL category lets a no-decryption rule match them by category rather than by individual address, satisfying the requirement to exclude that traffic from SSL Decryption. The firewall then bypasses decryption for those sessions while still applying other security policy, preserving privacy without disabling inspection globally.
- ✗
Configure a decryption profile to exclude traffic based on App-ID.
Why it's wrong here
Decryption profiles govern cipher suites, certificates and failure handling; they cannot select which traffic to decrypt, since exclusion is decided by the decryption policy's match criteria. It is tempting because App-ID appears in policy rules, and would be correct for enforcing application-specific security profiles on traffic already being decrypted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.