Palo Alto Networks Certified Network Security Engineer (PCNSE)Core ConceptsHard

A financial institution requires strict adherence to data privacy regulations. They want to decrypt SSL/TLS traffic on their Palo Alto Networks firewall to inspect for sensitive data exfiltration, but they must ensure that traffic to specific financial services websites (e.g., banking portals) is *not* decrypted due to legal and compliance reasons. Which decryption deployment method, combined with proper policy configuration, would best satisfy these requirements?

  1. ASSL Forward Proxy Decryption with a 'no-decrypt' rule for banking sites.
  2. BSSL Inbound Inspection with a 'no-decrypt' rule for banking sites.
  3. CSSH Proxy Decryption for all traffic and a bypass for banking sites.
  4. DNone, as decrypting sensitive financial traffic is always prohibited.
Show answer & explanation

Correct answer: A. SSL Forward Proxy Decryption with a 'no-decrypt' rule for banking sites.

SSL Forward Proxy Decryption is used to decrypt client-to-server outbound traffic, allowing the firewall to inspect web traffic for threats and data exfiltration. Crucially, it allows for granular control through decryption policies, where 'no-decrypt' rules can be configured for specific categories or URLs (like banking sites) to comply with regulations, while still decrypting other traffic.

Why the other options are wrong

  • B. SSL Inbound Inspection is for server-to-client traffic (e.g., inspecting traffic to an internal web server), not outbound client browsing.
  • C. SSH Proxy Decryption is for SSH traffic, not SSL/TLS web traffic, and is not the appropriate method.
  • D. While decrypting financial traffic often has legal implications, the question asks for a method that *allows selective non-decryption*, which Forward Proxy provides.

SSL Forward Proxy Decryption

A decryption method where the firewall acts as an intermediary, decrypting outbound SSL/TLS traffic from internal clients to external servers, and re-encrypting it before forwarding.

  • Used for client-to-server (outbound) traffic.
  • Requires installing a firewall root CA certificate on client devices.
  • Allows for 'no-decrypt' rules to bypass decryption for specific sites/categories.

Memory trick: Forward Proxy for outbound, Inbound for internal servers, selective is key!

More Core Concepts questions