Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security administrator is configuring a decryption policy on a Palo Alto Networks firewall. The company policy states that traffic to financial institutions and healthcare providers must NOT be decrypted due to privacy regulations, while all other outbound internet traffic SHOULD be decrypted and inspected. Which decryption type should be configured for the policy rule targeting financial/healthcare traffic?

  1. ANo Decrypt
  2. BSSL Forward Proxy
  3. CSSL Inbound Inspection
  4. DSSL Decryption Exemption
Show answer & explanation

Correct answer: A. No Decrypt

To prevent decryption for specific categories of traffic, the 'No Decrypt' action is used in a decryption policy rule. This allows the encrypted traffic to pass through without being intercepted and decrypted by the firewall, respecting privacy regulations. SSL Decryption Exemption is not a standard decryption type/action in this context; it's a feature for specific applications.

Why the other options are wrong

  • B. SSL Forward Proxy is the type of decryption *used* for outbound traffic that *is* decrypted.
  • C. SSL Inbound Inspection is for decrypting traffic *to* internal servers, not outbound traffic from internal users.
  • D. While the concept of exemption exists, 'No Decrypt' is the direct policy action to prevent decryption for specific traffic flows. 'SSL Decryption Exemption' is more of a configuration option for specific applications, not a decryption type for policy rules.

Decryption Policy 'No Decrypt'

The 'No Decrypt' action in a decryption policy rule prevents the firewall from intercepting and decrypting SSL/TLS traffic that matches the rule criteria.

  • Used for privacy, legal, or technical reasons.
  • Traffic passes through encrypted.
  • Rule order is critical, 'No Decrypt' rules should be placed above 'Decrypt' rules.

Memory trick: Decrypt or Not? Policy Decides.

More Security Policy Configuration questions