A company policy requires that all outbound web traffic from the internal network must be decrypted and inspected for threats, except for traffic destined for financial institutions. The Palo Alto Networks firewall is configured with a Decryption Policy. Which two decryption policy rules, in the correct order, would satisfy this requirement?
- ARule 1: Source: Trust, Destination: Untrust, URL Category: financial-services, Action: No Decryption. Rule 2: Source: Trust, Destination: Untrust, URL Category: any, Action: Decrypt.
- BRule 1: Source: Trust, Destination: Untrust, URL Category: financial-services, Action: Decrypt. Rule 2: Source: Trust, Destination: Untrust, URL Category: any, Action: No Decryption.
- CRule 1: Source: Trust, Destination: any, URL Category: financial-services, Action: No Decryption. Rule 2: Source: Trust, Destination: any, URL Category: any, Action: Decrypt.
- DRule 1: Source: Trust, Destination: Untrust, URL Category: any, Action: Decrypt. Rule 2: Source: Trust, Destination: Untrust, URL Category: financial-services, Action: No Decryption.
Show answer & explanationAnswer & explanation
Correct answer: A. Rule 1: Source: Trust, Destination: Untrust, URL Category: financial-services, Action: No Decryption. Rule 2: Source: Trust, Destination: Untrust, URL Category: any, Action: Decrypt.
Decryption policies are processed top-down. To exempt financial services traffic from decryption while decrypting all other web traffic, the 'No Decryption' rule for financial services must be placed *before* the 'Decrypt' rule for all other traffic. This ensures the specific exception is hit first.
Why the other options are wrong
- B. This order is incorrect because it attempts to decrypt financial services traffic, and then broadly disables decryption, which is the opposite of the requirement.
- C. While the order is correct, using 'Destination: any' is less specific than 'Destination: Untrust' for outbound web traffic, though it might technically work, 'Untrust' is more precise for external web destinations.
- D. This order is incorrect. The 'Decrypt' rule for 'any' would match and decrypt financial services traffic before the 'No Decryption' rule could be processed.
Decryption Policy Order
Decryption policies are evaluated in a top-down manner. More specific rules, especially those for 'No Decryption' exemptions, must be placed above more general 'Decrypt' rules.
- Decryption policies control which TLS/SSL traffic is decrypted for inspection.
- Rules are processed sequentially; the first match applies.
- Common exemptions include financial, healthcare, or privacy-sensitive websites.
- A 'No Decryption' rule for specific categories must precede a general 'Decrypt' rule.
Memory trick: Decryption: Specific exemptions first, then general rules, to keep secrets safe.