Courseiva
Decryption and SSL InspectioneasyMultiple SelectObjective-mapped

PCNSE Decryption and SSL Inspection Practice Question

Which TWO types of traffic should typically be excluded from SSL decryption for compliance or operational reasons? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Traffic to healthcare portals and electronic medical records.

Options C and D are correct because traffic to healthcare portals (e.g., electronic medical records) and financial services websites (e.g., banking, investment) must often be excluded from SSL decryption to comply with regulations such as HIPAA and PCI DSS, which restrict inspection of sensitive data. Option A is incorrect because social media traffic is typically not subject to specific compliance requirements that mandate exclusion. Option B is incorrect because traffic between internal data center servers, while potentially sensitive, is not typically excluded solely for compliance reasons; it may be decrypted for security monitoring. Option E is incorrect because external email services like Gmail can be decrypted for threat prevention, though some organizations may choose to exclude them for privacy, but it is not a standard compliance requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Traffic to social media websites.

    Why it's wrong here

    Typically not a compliance concern.

  • Traffic between internal data center servers.

    Why it's wrong here

    Internal traffic is often decrypted to detect lateral movement.

  • Traffic to healthcare portals and electronic medical records.

    Why this is correct

    HIPAA and other regulations may restrict decryption.

  • Traffic to financial services websites (e.g., banking, investment).

    Why this is correct

    Regulatory compliance may prohibit decryption of financial data.

  • Traffic to external email services (e.g., Gmail).

    Why it's wrong here

    Often decrypted for security.

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.