nerdexam
Palo_Alto_Networks

PCNSE · Question #556

An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)

The correct answer is A. URL categories B. source users C. source and destination IP addresses. PAN-OS SSL Decryption policy rules support several match criteria: URL categories (A), source users (B), and source/destination IP addresses (C) are all valid parameters. App-ID (D) cannot be used as a match criterion in SSL decryption rules because the application identity…

Submitted by zhang_li· Apr 18, 2026Deploy and Configure

Question

An engineer is tasked with enabling SSL decryption across the environment. What are three valid parameters of an SSL Decryption policy? (Choose three.)

Options

  • AURL categories
  • Bsource users
  • Csource and destination IP addresses
  • DApp-ID
  • EGlobalProtect HIP

How the community answered

(28 responses)
  • A
    89% (25)
  • D
    7% (2)
  • E
    4% (1)

Explanation

PAN-OS SSL Decryption policy rules support several match criteria: URL categories (A), source users (B), and source/destination IP addresses (C) are all valid parameters. App-ID (D) cannot be used as a match criterion in SSL decryption rules because the application identity cannot be determined until after the session is decrypted - using it as a pre-decryption match criterion creates a logical impossibility. GlobalProtect HIP profiles (E) are not valid match parameters within SSL decryption policies.

Topics

#SSL Decryption#Decryption Policy#Policy Parameters#Security Policies

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice