Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A company is deploying a new internal web application that uses a custom TCP port 4443. The security team needs to ensure that all outbound connections from this application to external services are decrypted for inspection, but other internal applications using standard SSL/TLS (port 443) should not be decrypted due to privacy concerns. Which decryption policy rule configuration will achieve this specific requirement?

  1. ACreate a 'Decrypt' rule for service 'any' and a 'No Decrypt' rule for service 'service-https', with the 'No Decrypt' rule ordered first.
  2. BCreate a 'Decrypt' rule for service 'tcp-4443' and a 'No Decrypt' rule for service 'service-https', with the 'Decrypt' rule ordered first.
  3. CCreate a 'Decrypt' rule for service 'tcp-4443' and a 'No Decrypt' rule for service 'application-default', with the 'Decrypt' rule ordered first.
  4. DCreate a 'No Decrypt' rule for service 'any' and a 'Decrypt' rule for service 'tcp-4443', with the 'No Decrypt' rule ordered first.
Show answer & explanation

Correct answer: B. Create a 'Decrypt' rule for service 'tcp-4443' and a 'No Decrypt' rule for service 'service-https', with the 'Decrypt' rule ordered first.

Decryption policies are evaluated top-down. To decrypt only the custom port 4443 while explicitly NOT decrypting standard HTTPS (port 443), the specific 'Decrypt' rule for 'tcp-4443' must be placed before the more general 'No Decrypt' rule for 'service-https'. This ensures the custom application is decrypted first, and then standard HTTPS traffic is explicitly excluded. Using 'application-default' or 'any' in the 'No Decrypt' rule would be too broad and might prevent decryption of other desired traffic.

Why the other options are wrong

  • A. A 'Decrypt' rule for 'any' would attempt to decrypt all SSL/TLS, which violates the privacy concern for other internal applications. Ordering 'No Decrypt' for 'service-https' first with 'Decrypt any' later would still not achieve the desired precise decryption of only 4443.
  • C. Using 'application-default' in the 'No Decrypt' rule might be too broad; 'service-https' (port 443) is more precise for standard SSL/TLS. Also, 'application-default' might not include 443 specifically if App-ID sees other applications on 443 that you might want to decrypt.
  • D. Ordering 'No Decrypt' for 'any' first would prevent decryption of 'tcp-4443' as well, failing the requirement.

Decryption Policy Order

Decryption policies are evaluated in order from top to bottom. Specific rules should be placed before more general rules to ensure desired decryption or non-decryption behavior.

  • Rules are processed sequentially.
  • First match determines action (decrypt or no decrypt).
  • More specific rules should precede more general rules.
  • 'No Decrypt' rules can be used to bypass decryption for sensitive traffic.

Memory trick: Decryption policy is like a bouncer at two doors: the specific door (4443) is checked first, then the general door (443).

More Security Policy Configuration questions