Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateMedium

A company policy dictates that all outbound HTTPS traffic must be decrypted for inspection, except for connections to financial institutions. The security engineer has created a Decryption Profile and a Decryption Policy rule to decrypt traffic. To exclude financial institutions, which component should be used in the Decryption Policy rule and how should it be configured?

  1. AA URL Category object set to 'no-decrypt' for financial sites, placed above the decrypt rule.
  2. BA Security Policy rule with 'no-decrypt' action for financial sites, placed above the decrypt rule.
  3. CA Decryption Policy rule with 'no-decrypt' action for financial sites, placed above the decrypt rule.
  4. DA Decryption Profile with 'no-decrypt' action for financial sites, applied to the decrypt rule.
Show answer & explanation

Correct answer: C. A Decryption Policy rule with 'no-decrypt' action for financial sites, placed above the decrypt rule.

Decryption policies are evaluated top-down, similar to security policies. To exclude specific traffic from decryption, a 'no-decrypt' rule targeting that traffic must be placed *above* the general 'decrypt' rule. This ensures the exclusion is processed first.

Why the other options are wrong

  • A. URL categories are used in security policy or decryption policy match criteria, but the 'no-decrypt' action is set in the policy rule itself, not directly in the URL category object.
  • B. Security policies determine if traffic is allowed or denied, not if it's decrypted. Decryption policies handle decryption actions.
  • D. Decryption profiles define *how* decryption occurs (e.g., forward trust, forward untrust), not *whether* decryption occurs for specific traffic. The action is set in the policy rule.

Decryption Policy Order

Decryption policies are evaluated in order from top to bottom. To create exceptions (e.g., no-decrypt for specific sites), those exception rules must be placed higher in the policy list than the general decrypt rules.

  • Decryption policies follow top-down evaluation.
  • 'No-decrypt' rules take precedence over 'decrypt' rules.
  • Used to manage SSL/TLS decryption for inspection or exclusion.

Memory trick: Exceptions 'no-decrypt' always go first, like VIPs skipping the security line.

More Manage and Operate questions