Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateHard

A company policy mandates that all outbound HTTPS traffic from the 'Internal-User' zone to the 'Untrust' zone must be decrypted for inspection, except for traffic destined to financial websites and healthcare providers. How should this decryption policy be configured to balance security inspection with privacy and compliance requirements?

  1. ACreate a 'decrypt' rule for all HTTPS traffic, and then manually add specific financial/healthcare domains to a 'no-decrypt' list.
  2. BCreate a 'no-decrypt' rule for financial and healthcare URL categories, placed above a 'decrypt' rule for all other HTTPS traffic.
  3. CConfigure a general 'decrypt' rule for the 'Internal-User' to 'Untrust' zone, and enable 'SSL Forward Proxy' without further policy.
  4. DCreate a 'no-decrypt' rule for financial and healthcare URL categories, placed below a 'decrypt' rule for all other HTTPS traffic.
Show answer & explanation

Correct answer: B. Create a 'no-decrypt' rule for financial and healthcare URL categories, placed above a 'decrypt' rule for all other HTTPS traffic.

Decryption policies are evaluated in order from top to bottom. To achieve the desired outcome, a 'no-decrypt' rule for the exempted categories (financial, healthcare) must be placed *above* a broader 'decrypt' rule that applies to all other HTTPS traffic. This ensures that the exceptions are processed first.

Why the other options are wrong

  • A. Manually adding domains is not scalable or maintainable; using URL categories is the correct approach. Also, the order still matters for the 'decrypt' rule.
  • C. Enabling 'SSL Forward Proxy' is a prerequisite, but it needs to be combined with a decryption policy that correctly handles exceptions based on policy order.
  • D. Placing the 'no-decrypt' rule below a 'decrypt' rule would mean the 'decrypt' rule is hit first, and all traffic (including financial/healthcare) would be decrypted, violating the policy.

Palo Alto Networks Decryption Policy Order

Palo Alto Networks decryption policies are evaluated from top to bottom. More specific 'no-decrypt' rules must be placed above broader 'decrypt' rules to ensure exceptions are correctly handled before general decryption applies.

  • Policies evaluated top-down.
  • Specific exceptions must be higher in the rulebase.
  • Incorrect order can lead to unintended decryption or non-decryption.

Memory trick: Decryption Order: Specific Exclusions FIRST, then General Decrypt.

More Manage and Operate questions