You must be able to explain App-ID misidentification causes, create custom App-IDs for proprietary protocols, and use application-based policies to block BitTorrent while allowing SFTP on the same port. The most important thing is that App-ID identifies applications by signature, not port.
Start practicing
Securing Traffic and App-ID — choose a session length
Free · No account required
Domain overview
This domain covers App-ID classification and policy enforcement on Palo Alto Networks firewalls. Questions test why App-ID misidentifies traffic, how to block applications like BitTorrent while allowing SFTP on the same port, and how to handle unknown-tcp or custom UDP protocols using application overrides and custom App-IDs.
Exam objectives
App-ID identification of applications using ports, signatures, and protocol decoders
Creating custom App-IDs for proprietary TCP or UDP protocols
Using application filters and groups to block file-sharing like BitTorrent
Troubleshooting unknown-tcp and unknown-udp in traffic logs
Assuming port-based rules can block BitTorrent while allowing SFTP on port 22; App-ID decodes the application regardless of port.
Forgetting that custom App-IDs require signature and context configuration; incomplete definitions cause unknown-tcp.
Believing App-ID will identify proprietary protocols without custom signatures; unknown-tcp appears until a custom App-ID is created.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a security audit, it is discovered that some HTTP traffic is being incorrectly identified as 'web-browsing' instead of 'ssl' even though the traffic uses HTTPS. The firewall is positioned as a transparent bridge and no SSL decryption is configured. What is the most likely cause?
2A network administrator wants to allow only specific applications such as 'facebook-base' and 'youtube' while blocking all other applications. Which type of security rule should be used to achieve this?
3A company deploys a Palo Alto Networks firewall in a data center. They have a critical application that uses a proprietary protocol over UDP port 12345. The firewall is not correctly identifying the traffic as the custom App-ID they created. They have verified that the custom App-ID is correctly configured and committed. What is the most likely cause?
4Which THREE of the following can cause App-ID to incorrectly identify traffic?
5Refer to the exhibit. A firewall administrator is troubleshooting why some applications are not being correctly identified. The firewall is running App-ID version 8000-7120. What does the 'appid packet buffer: 1024 KB' indicate?
6A company uses App-ID to identify traffic on their Palo Alto Networks firewall. They notice that a particular application, custom-db-sync, is not being identified correctly. The traffic uses a proprietary protocol over TCP port 4444. The firewall currently has a security rule allowing any application on that port. Which step should the engineer take to enable App-ID to correctly identify custom-db-sync?
7Order the steps to configure a security policy allowing HTTP traffic from the inside to the outside zone.
8Order the steps to upgrade the PAN-OS software on a standalone firewall.
9An administrator needs to create a custom application for a proprietary database protocol that uses TCP port 7890. What is the first step in defining this application in App-ID?
10A network engineer notices that traffic from an internal user to a web application is being incorrectly identified as 'web-browsing' instead of the custom application 'my-app'. The engineer has already created a custom application 'my-app' with the correct signature. What is the most likely reason for the misidentification?
11An engineer wants to block the use of file-sharing application BitTorrent, but allow file transfers over SFTP which also uses port 22. What is the most effective way to achieve this using App-ID?
12During an audit, it is discovered that some traffic from a legacy application is being incorrectly identified as 'ssl' because the application uses a custom encryption scheme over TCP port 443. The engineer has created a custom application signature that matches the legacy application's handshake. What additional configuration is needed to ensure the legacy application is correctly identified?
13An engineer is configuring App-ID for a network that uses both standard and custom applications. Which of the following are best practices for using App-ID effectively? (Choose three.)
14An engineer checks the application counter and sees that my-custom-app has zero packets, but they expected traffic from 10.0.0.0/24 to 10.1.0.0/24 to be identified as my-custom-app. What is the most likely reason?
15An organization has two different applications (AppA and AppB) that both use TCP port 8080. The firewall must apply different security policies to each application. What is the recommended approach?
16A firewall shows session logs with application 'incomplete' for many SSL connections. Which action should be taken to improve App-ID accuracy?
17A network engineer wants to reduce the number of applications in security policies by combining several applications that are always used together. What is the best practice?
18During a security audit, it is discovered that a custom application signature matches too broadly, causing benign traffic to be classified as the custom app. What change should be made to narrow the signature?
19Which TWO factors can cause traffic to be classified as 'incomplete' by App-ID? (Choose two.)
20Which TWO are best practices when configuring App-ID for a production environment? (Choose two.)
21A company has an application signature for an internal ERP system that uses a proprietary protocol over TCP port 4444. The ERP traffic is sometimes misidentified as unknown-tcp. Which App-ID mechanism should be used to improve identification without affecting the default App-ID engine?
22An organization uses a SaaS application that runs on a dynamic set of IP addresses. The application traffic is currently identified as ssl and not as the specific application. How can the administrator improve application identification for this SaaS application?
23Which TWO settings must be configured in a security policy rule to ensure the rule only matches when a specific application is detected on its standard port?
24Refer to the exhibit. An administrator notices that HTTPS traffic to a specific website is being denied. What is the most likely cause?
25A company uses a Palo Alto Networks firewall with App-ID enabled. They have a custom application that communicates over TCP port 5001. The administrator has created a custom App-ID signature and a security rule that allows this application from the internal zone (trust) to the external zone (untrust). Users report that the custom application traffic is being blocked. The administrator checks the traffic logs and sees that the sessions are being matched to a different security rule that denies any traffic from trust to untrust. The deny rule appears before the custom allow rule in the policy list. The custom App-ID signature is properly defined and tested. What should the administrator do to resolve this issue?
26A network security engineer is troubleshooting an application that is inconsistently identified as 'unknown-tcp' in the traffic logs. The application uses TCP port 8080 and initiates with a proprietary binary handshake. The engineer confirms that no custom App-ID has been created. Which action should the engineer take to ensure the firewall reliably identifies this application?
27A security administrator is configuring App-ID to distinguish between a sanctioned SaaS application and an unsanctioned one that both use HTTPS on TCP port 443. The administrator wants the firewall to identify the sanctioned application by inspecting the TLS handshake and certificate details. Which firewall feature should be enabled to achieve this?
28A security administrator is troubleshooting why a custom application that uses SSL/TLS on TCP port 9443 is being identified as 'ssl' instead of the custom App-ID. The firewall has a security policy that allows 'ssl' and the custom application. The administrator has already confirmed that the traffic passes through the firewall and that SSL decryption is not enabled. Which action should the administrator take to allow App-ID to correctly identify the application?
29A security administrator is configuring an outbound security policy for a new SaaS application. The application uses multiple dynamic ports and occasionally changes its server IPs. The administrator wants to allow only this application while blocking all other traffic on those ports. Which Palo Alto Networks feature should be used to identify and control this application?
30A security administrator is reviewing traffic logs and notices that a known application is being identified as 'web-browsing' instead of its correct App-ID. The application uses HTTP and is not encrypted. The administrator confirms that the application is not a custom application. What is the most likely cause of this misidentification?
31A security engineer is configuring a security policy to allow only the specific business application 'salesforce' while blocking all other applications that use HTTPS. The firewall is not performing SSL decryption. What will be the result of the security policy?
32A security administrator is configuring a security policy to allow the 'web-browsing' application but block the 'facebook' application. The administrator creates a rule that allows 'web-browsing' and a subsequent rule that denies 'facebook'. However, users report that they can still access Facebook. The administrator checks the traffic logs and sees that Facebook traffic is being identified as 'web-browsing'. Which action should the administrator take to correctly block Facebook?
33A security administrator is troubleshooting App-ID on a firewall that is deployed in a Layer 2 transparent mode. The administrator notices that some applications are not being identified correctly, even though the traffic is not encrypted. What is the most likely reason for this issue?
34A security engineer is troubleshooting why a web application is not being identified correctly. The firewall shows the session as 'ssl' instead of the specific application. The engineer has verified that the traffic is using TLS 1.3. What is the most likely reason for the misidentification?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
You must be able to explain App-ID misidentification causes, create custom App-IDs for proprietary protocols, and use application-based policies to block BitTorrent while allowing SFTP on the same port. The most important thing is that App-ID identifies applications by signature, not port.
The Courseiva PCNSE question bank contains 34 questions in the Securing Traffic and App-ID domain, covering the 7% of the exam attributed to this domain in the official Palo Alto Networks blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Securing Traffic and App-ID domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included