PCNSA App-ID and Content-ID Practice Question
A company's security policy must allow Microsoft Teams traffic but deny all other chat applications. Which type of object should be specified in the 'Application' column of the security policy rule?
⚠ Common exam trap
It's easy for candidates to confuse application objects with service objects, thinking that port-based rules (e.g., allowing TCP 443) are sufficient to permit Microsoft Teams, but App-ID requires the application object to differentiate Teams from other HTTPS-based chat apps like Slack or WhatsApp Web.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application object for Microsoft Teams.
The security policy rule's 'Application' column requires a specific application object to match traffic identified by App-ID. An application object for Microsoft Teams allows the firewall to identify and permit Teams traffic based on its unique application signatures, including its underlying protocols (e.g., HTTPS, STUN, TURN) and cloud endpoints, while blocking all other chat applications by default.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Application Filter with conditions matching Microsoft Teams.
Why it's wrong here
Filters are used to dynamically match applications, not to explicitly allow one.
- ✓
Application object for Microsoft Teams.
Why this is correct
Directly specifying the application object allows only that app.
- ✗
Service object for Microsoft Teams' ports.
Why it's wrong here
Service objects define ports, not applications.
- ✗
Application Group named 'Chat_Apps' containing all chat apps.
Why it's wrong here
An Application Group would include multiple apps, not just Microsoft Teams.
Go deeper
Related to this question
About these practice questions
One of 516 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.