PCNSE Core Concepts and Architecture Practice Question
An administrator is configuring a Palo Alto Networks firewall to perform SSL decryption for outbound traffic. The administrator wants to ensure that traffic to certain categories, such as financial services, is not decrypted due to privacy concerns. What should the administrator configure?
⚠ Common exam trap
Candidates often confuse decryption policy with Security policy; a Security policy deny would block traffic, not just bypass decryption, and decryption profiles do not control which traffic is decrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A decryption policy rule with the action 'no-decrypt' for the financial services category.
To exclude specific traffic from SSL decryption, the administrator should create a decryption policy rule with the action 'no-decrypt' for the desired category or traffic. This rule must be placed above the decryption rule that would otherwise decrypt the traffic. This ensures that traffic to financial services is not decrypted while other traffic can still be decrypted as needed. The no-decrypt action is specifically designed for this purpose, allowing selective bypass of decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A decryption policy rule with the action 'no-decrypt' for the financial services category.
Why this is correct
A decryption policy rule with the action 'no-decrypt' allows the administrator to exclude specific traffic from SSL decryption based on criteria such as URL category. By placing this rule above the decryption rule, traffic to financial services will be exempt from decryption, addressing privacy concerns. This is the correct way to selectively bypass decryption for certain categories.
- ✗
A decryption profile with the 'no-decrypt' setting for the financial services category.
Why it's wrong here
A decryption profile is used to define settings for decrypted traffic, such as certificate validation and unsupported protocol handling. It does not determine which traffic is decrypted or bypassed. The decision to decrypt or not is made by decryption policy rules. Therefore, configuring a decryption profile with no-decrypt is not the correct method; the no-decrypt action is set in the decryption policy rule.
- ✗
A decryption policy rule with the action 'decrypt' for all traffic except financial services.
Why it's wrong here
While this approach could work by creating a decrypt rule for all traffic and then a no-decrypt rule for financial services above it, the option as stated is incomplete. A single decrypt rule for all traffic except financial services is not possible; decryption policy rules are evaluated top-down, so you need a no-decrypt rule for financial services above a decrypt rule for the rest. The option implies a single rule with an exception, which is not how PAN-OS decryption policy works.
- ✗
A Security policy rule with the action 'deny' for the financial services category.
Why it's wrong here
A Security policy rule with a deny action would block the traffic entirely, not just bypass decryption. The administrator wants to allow the traffic but not decrypt it. Using a deny rule would prevent users from accessing financial services, which is not the intended outcome. The correct approach is to use a decryption policy rule with no-decrypt action, not a Security policy deny.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.