The SSL Decryption Exclusion list allows administrators to specify domains that should never be decrypted, based on the server certificate's CN or SAN. Adding the specific banking website's domain ensures that traffic to that site bypasses decryption, addressing privacy concerns. This is the most granular method for excluding individual sites without affecting others.
Why this answer
The SSL Decryption Exclusion list is designed to bypass decryption for specific domains based on the server certificate's CN or SAN. Adding the banking website's domain ensures that traffic to that site is not decrypted, addressing privacy concerns without affecting other traffic. Other options either apply too broadly, block traffic incorrectly, or do not provide selective exclusion.
Exam trap
The trap here is confusing the SSL Decryption Exclusion list with decryption policy rules; the exclusion list is specifically for excluding sites by domain without creating a policy rule.