Question 1
Q1A security architect is designing a decryption strategy for a high-security financial institution. The organization requires inspection of outbound SSL/TLS traffic to detect data exfiltration. However, strict privacy regulations mandate that personal banking and healthcare traffic must NEVER be decrypted. Which configuration strategy optimally balances security visibility with regulatory compliance?
Show answer & explanation
Correct answer: B
Palo Alto Networks firewalls process decryption policy rules from top to bottom. To satisfy the requirement, specific traffic (sensitive categories) must be explicitly excluded from decryption using a 'No Decrypt' action before the general rule that decrypts remaining traffic is evaluated. Blocking the categories would prevent business continuity, not just stop decryption.