Which feature must be configured to exclude sensitive traffic from decryption?

-Security policy rule that includes the specific URL with an "allow" action

-Decryption policy rule with the specific URL and "no decrypt" action

-Application Override policy that matches the application URL and port number

-Decryption Profile that includes the site's URL