Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureHard

A security auditor requires that all HTTP/HTTPS traffic from the internal network to the internet must be inspected for malware and blocked if threats are detected. However, traffic to a specific financial institution's website must bypass SSL decryption due to compliance reasons. Which decryption configuration is required to meet these requirements?

  1. ASSL Forward Proxy with a Decryption Profile and a 'No Decrypt' rule for the financial site.
  2. BSSL Forward Proxy with a Decryption Policy and a 'No Decrypt' rule for the financial site.
  3. CSSL Inbound Inspection with a Decryption Profile and a 'No Decrypt' rule for the financial site.
  4. DSSL Inbound Inspection with a Decryption Policy and a 'No Decrypt' rule for the financial site.
Show answer & explanation

Correct answer: B. SSL Forward Proxy with a Decryption Policy and a 'No Decrypt' rule for the financial site.

To inspect outbound HTTP/HTTPS traffic, SSL Forward Proxy decryption is used. A Decryption Policy is required to define which traffic to decrypt and which to exclude, such as with a 'No Decrypt' rule for specific destinations like the financial site.

Why the other options are wrong

  • A. Decryption Profiles define decryption settings (e.g., block sessions with untrusted certs) but don't specify what traffic to decrypt; Decryption Policies do.
  • C. SSL Inbound Inspection is incorrect, and Decryption Profiles don't govern traffic selection for decryption.
  • D. SSL Inbound Inspection is for traffic coming INTO a server protected by the firewall, not outbound user traffic.

SSL Forward Proxy Decryption with Decryption Policy

SSL Forward Proxy decrypts outbound encrypted traffic from internal users to external destinations by acting as a man-in-the-middle. A Decryption Policy defines the rules for which traffic to decrypt, block, or exclude from decryption.

  • Used for outbound encrypted traffic from internal clients to external servers.
  • Requires a Decryption Policy to specify traffic for decryption or exclusion.
  • A 'No Decrypt' rule can bypass decryption for specific destinations/sources.
  • Requires a Forward Trust Certificate and a Forward Untrust Certificate.

Memory trick: Forward your proxy, then policy the bypass.

More Deploy and Configure questions