Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignHard
A network security architect is designing a decryption policy for an organization that requires full visibility into all encrypted traffic, except for specific applications related to sensitive financial and healthcare data due to compliance reasons. The design must ensure that these compliant applications are never decrypted. Which decryption policy rule order and type combination should be prioritized?
- AA 'no-decrypt' rule for compliant applications at the top of the decryption policy.
- BA 'no-decrypt' rule for compliant applications at the bottom of the decryption policy.
- CA 'decrypt' rule for all traffic at the top, followed by a 'no-decrypt' rule for compliant applications.
- DA default 'decrypt' rule for all traffic, with compliant applications explicitly excluded in the decryption profile.
Show answer & explanationAnswer & explanation
Correct answer: A. A 'no-decrypt' rule for compliant applications at the top of the decryption policy.
Decryption policies are evaluated from top to bottom. To ensure sensitive applications are never decrypted, a 'no-decrypt' rule specifically for those applications must be placed at the very top of the decryption policy, before any 'decrypt' rules. This ensures they are matched and excluded from decryption first.
Why the other options are wrong
- B. Placing a 'no-decrypt' rule at the bottom means it might be superseded by a 'decrypt' rule higher up, leading to decryption of sensitive traffic.
- C. A 'decrypt' rule at the top would decrypt the compliant applications before the 'no-decrypt' rule is ever evaluated, failing to meet the requirement.
- D. While decryption profiles can exclude categories, a dedicated 'no-decrypt' rule at the top provides explicit and guaranteed exclusion, which is critical for compliance, especially when a general 'decrypt' rule is also present.
Decryption Policy Rule Order
The sequential evaluation of decryption policy rules from top to bottom, where the first matching rule is applied.
- Crucial for ensuring specific traffic is either decrypted or explicitly not decrypted.
- Specific 'no-decrypt' rules should generally be placed above general 'decrypt' rules.
- Compliance requirements often dictate strict rule ordering for sensitive data.
Memory trick: First come, first served, especially for no-decrypt.