nerdexam
Palo_Alto_Networks

PCNSE · Question #636

An administrator is assisting a security engineering team with a decryption rollout for inbound and forward proxy traffic. Incorrect firewall sizing is preventing the team from decrypting all of the…

The correct answer is C. Known malicious IP space D. High-risk traffic categories E. Public-facing servers. When firewall resources limit the scope of decryption, prioritizing traffic that poses the highest security risk or targets critical assets is essential.

Submitted by priya_blr· Apr 18, 2026Plan

Question

An administrator is assisting a security engineering team with a decryption rollout for inbound and forward proxy traffic. Incorrect firewall sizing is preventing the team from decrypting all of the traffic they want to decrypt. Which three items should be prioritized for decryption? (Choose three.)

Options

  • AFinancial, health, and government traffic categories
  • BLess-trusted internal IP subnets
  • CKnown malicious IP space
  • DHigh-risk traffic categories
  • EPublic-facing servers

How the community answered

(57 responses)
  • A
    9% (5)
  • B
    19% (11)
  • C
    72% (41)

Why each option

When firewall resources limit the scope of decryption, prioritizing traffic that poses the highest security risk or targets critical assets is essential.

AFinancial, health, and government traffic categories

Financial, health, and government traffic categories often contain highly sensitive personal data and are frequently *excluded* from decryption policies due to strict privacy regulations and compliance requirements, rather than prioritized for inspection.

BLess-trusted internal IP subnets

While traffic from less-trusted internal IP subnets might warrant inspection, the focus for *initial* decryption rollout under resource constraints for inbound and forward proxy traffic is typically on external threats and critical assets, not internal network segments.

CKnown malicious IP spaceCorrect

Prioritizing decryption for known malicious IP space ensures that the firewall can thoroughly inspect potential threat communications to or from compromised entities, helping to detect and prevent advanced attacks.

DHigh-risk traffic categoriesCorrect

Decrypting high-risk traffic categories (e.g., P2P, anonymizers, unrated URLs) allows the firewall to apply threat prevention and data filtering policies to obscure traffic that is more likely to contain malware or policy violations.

EPublic-facing serversCorrect

Decrypting traffic destined for public-facing servers enables the firewall to inspect inbound encrypted connections for exploits, web application attacks, and other threats targeting critical external-facing infrastructure.

Concept tested: Decryption prioritization in resource-constrained environments

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/decryption/decryption-deployment-best-practices/outline-your-decryption-policy

Topics

#SSL Decryption#Traffic Prioritization#Threat Prevention#Security Best Practices

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice