PCNSE Decryption and SSL Inspection Practice Question
Which TWO types of traffic should typically be excluded from SSL decryption for compliance or operational reasons? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Traffic to healthcare portals and electronic medical records.
Options C and D are correct because traffic to healthcare portals (e.g., electronic medical records) and financial services websites (e.g., banking, investment) must often be excluded from SSL decryption to comply with regulations such as HIPAA and PCI DSS, which restrict inspection of sensitive data. Option A is incorrect because social media traffic is typically not subject to specific compliance requirements that mandate exclusion. Option B is incorrect because traffic between internal data center servers, while potentially sensitive, is not typically excluded solely for compliance reasons; it may be decrypted for security monitoring. Option E is incorrect because external email services like Gmail can be decrypted for threat prevention, though some organizations may choose to exclude them for privacy, but it is not a standard compliance requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Traffic to social media websites.
Why it's wrong here
Typically not a compliance concern.
- ✗
Traffic between internal data center servers.
Why it's wrong here
Internal traffic is often decrypted to detect lateral movement.
- ✓
Traffic to healthcare portals and electronic medical records.
Why this is correct
HIPAA and other regulations may restrict decryption.
- ✓
Traffic to financial services websites (e.g., banking, investment).
Why this is correct
Regulatory compliance may prohibit decryption of financial data.
- ✗
Traffic to external email services (e.g., Gmail).
Why it's wrong here
Often decrypted for security.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.