nerdexam
Palo_Alto_Networks

PCNSE · Question #296

Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)

The correct answer is A. Create a no-decrypt Decryption Policy rule. E. Enable the "Block sessions with untrusted issuers" setting.. You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not dec

Submitted by takeshi77· Apr 18, 2026Deploy and Configure

Question

Which two actions would be part of an automatic solution that would block sites with untrusted certificates without enabling SSL Forward Proxy? (Choose two.)

Options

  • ACreate a no-decrypt Decryption Policy rule.
  • BConfigure an EDL to pull IP addresses of known sites resolved from a CRL.
  • CCreate a Dynamic Address Group for untrusted sites
  • DCreate a Security Policy rule with vulnerability Security Profile attached.
  • EEnable the "Block sessions with untrusted issuers" setting.

How the community answered

(40 responses)
  • A
    83% (33)
  • B
    3% (1)
  • C
    10% (4)
  • D
    5% (2)

Explanation

You can use the No Decryption tab to enable settings to block traffic that is matched to a decryption policy configured with the No Decrypt action ( Policies > Decryption > Action). Use these options to control server certificates for the session, though the firewall does not decrypt and inspect the session traffic. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-concepts/no- decryption-decryption-profile

Topics

#SSL Decryption Policy#Certificate Validation#Untrusted Issuers Blocking#Decryption Profile Settings

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice