nerdexam
Palo_Alto_NetworksPalo_Alto_Networks

PCNSE · Question #221

PCNSE Question #221: Real Exam Question with Answer & Explanation

Sign in or unlock PCNSE to reveal the answer and full explanation for question #221. The question stem and answer options stay visible for context.

Submitted by cyberguy42· Apr 18, 2026Deploy and Configure

Question

An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing. The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are three entries. The first entry shows traffic dropped as application Unknown. The next two entries show traffic allowed as application SSL. Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?

Options

  • ACreate a decryption rule matching the encrypted BitTorrent traffic with action "No- Decrypt," and
  • BCreate a Security policy rule that matches application "encrypted BitTorrent" and place the rule at
  • CDisable the exclude cache option for the firewall.
  • DCreate a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the

Unlock PCNSE to see the answer

You've previewed enough free PCNSE questions. Unlock PCNSE for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#SSL Decryption#Application Identification#Decryption Profile#Traffic Logging
Full PCNSE PracticeBrowse All PCNSE Questions