nerdexam
Palo_Alto_Networks

PCNSE · Question #221

An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing. The…

The correct answer is D. Create a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the. After the first BitTorrent connection is identified and dropped, subsequent connections from the same endpoints may appear as 'SSL' in the traffic log because App-ID caches the result and subsequent connections match before full reclassification occurs. BitTorrent clients often…

Submitted by cyberguy42· Apr 18, 2026Deploy and Configure

Question

An administrator creates an SSL decryption rule decrypting traffic on all ports. The administrator also creates a Security policy rule allowing only the applications DNS, SSL, and web-browsing. The administrator generates three encrypted BitTorrent connections and checks the Traffic logs. There are three entries. The first entry shows traffic dropped as application Unknown. The next two entries show traffic allowed as application SSL. Which action will stop the second and subsequent encrypted BitTorrent connections from being allowed as SSL?

Options

  • ACreate a decryption rule matching the encrypted BitTorrent traffic with action "No- Decrypt," and
  • BCreate a Security policy rule that matches application "encrypted BitTorrent" and place the rule at
  • CDisable the exclude cache option for the firewall.
  • DCreate a Decryption Profile to block traffic using unsupported cyphers, and attach the profile to the

How the community answered

(40 responses)
  • A
    15% (6)
  • B
    10% (4)
  • C
    3% (1)
  • D
    73% (29)

Explanation

After the first BitTorrent connection is identified and dropped, subsequent connections from the same endpoints may appear as 'SSL' in the traffic log because App-ID caches the result and subsequent connections match before full reclassification occurs. BitTorrent clients often use non-standard or weak TLS cipher suites that are not compliant with standard SSL/TLS specifications. By creating a Decryption Profile that blocks sessions using unsupported or unknown cipher suites and attaching it to the decryption rule, the NGFW will block these BitTorrent connections before they can be misidentified as legitimate SSL traffic. This addresses the root cause at the decryption layer rather than relying solely on App-ID reclassification.

Topics

#SSL Decryption#Application Identification#Decryption Profile#Traffic Logging

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice