Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignMedium
A network security architect is designing a decryption policy for an organization that has strict privacy requirements, prohibiting the decryption of traffic to financial and healthcare websites. All other outbound web traffic must be decrypted for threat inspection. Which decryption policy rule type should be used to ensure that sensitive categories are never decrypted, while allowing decryption for all other relevant traffic?
- ASSL Forward Proxy
- BSSL Inbound Inspection
- CNo Decrypt
- DDecrypt
Show answer & explanationAnswer & explanation
Correct answer: C. No Decrypt
A 'No Decrypt' decryption policy rule is used to explicitly prevent decryption for specified traffic, such as sensitive categories like financial and healthcare. This rule should be placed higher in the rule order than a 'Decrypt' rule to ensure these exceptions are always honored.
Why the other options are wrong
- A. SSL Forward Proxy is a decryption *method*, not a rule type. It defines how decryption is performed (for outbound traffic).
- B. SSL Inbound Inspection is a decryption *method* for inbound traffic to internal servers, not a rule type for exempting categories.
- D. A 'Decrypt' rule type actively decrypts traffic. While it would handle other traffic, it would overwrite the privacy requirement if not preceded by a 'No Decrypt' rule.
Decryption Policy Rule Types
Palo Alto Networks decryption policy rules define whether traffic is decrypted ('Decrypt' rule) or explicitly not decrypted ('No Decrypt' rule) based on matching criteria.
- 'No Decrypt' rules take precedence over 'Decrypt' rules.
- Used for privacy, compliance, or technical exclusions.
- Essential for managing SSL/TLS traffic inspection.
- Order of rules matters significantly.
Memory trick: Decryption rules either 'DO' it or 'DON'T' do it based on 'CATEGORY'.