Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A security engineer is configuring a decryption policy on a Palo Alto Networks firewall. The company policy states that all traffic to financial institutions (identified by a custom URL category 'Financial-Sites') must NOT be decrypted due to privacy and compliance regulations. All other internet-bound HTTPS traffic should be decrypted. In which order should the decryption policy rules be arranged?
- ARule 1: Source 'any', Destination 'Financial-Sites', Action 'Decrypt'. Rule 2: Source 'any', Destination 'any', Action 'No Decrypt'.
- BRule 1: Source 'any', Destination 'any', Action 'Decrypt'. Rule 2: Source 'any', Destination 'Financial-Sites', Action 'No Decrypt'.
- CRule 1: Source 'any', Destination 'any', Action 'No Decrypt'. Rule 2: Source 'any', Destination 'Financial-Sites', Action 'Decrypt'.
- DRule 1: Source 'any', Destination 'Financial-Sites', Action 'No Decrypt'. Rule 2: Source 'any', Destination 'any', Action 'Decrypt'.
Show answer & explanationAnswer & explanation
Correct answer: D. Rule 1: Source 'any', Destination 'Financial-Sites', Action 'No Decrypt'. Rule 2: Source 'any', Destination 'any', Action 'Decrypt'.
Decryption policies are evaluated in order from top to bottom. To ensure that traffic to financial sites is explicitly NOT decrypted while all other traffic IS decrypted, the more specific 'No Decrypt' rule for financial sites must be placed above the broader 'Decrypt' rule.
Why the other options are wrong
- A. This order would attempt to decrypt financial sites (violating policy) and then block decryption for everything else, which is not the desired outcome.
- B. This order would cause all traffic, including financial sites, to be decrypted by the first rule, violating the company policy.
- C. This order would prevent all traffic from being decrypted by the first rule, which is contrary to the requirement to decrypt 'all other internet-bound HTTPS traffic'.
Decryption Policy Order
Decryption policies on Palo Alto Networks firewalls are processed sequentially from top to bottom. More specific rules, especially those with 'No Decrypt' actions, must be placed above broader 'Decrypt' rules to ensure correct enforcement.
- Top-down processing order.
- Specific rules should precede general rules.
- 'No Decrypt' rules for sensitive traffic are often prioritized.
Memory trick: Specific First, Then Broad.