PCNSA App-ID and Content-ID Practice Question
A medium-sized enterprise has a Palo Alto Networks firewall in your data center. They have recently deployed a new cloud-based CRM system that uses a proprietary protocol over TCP port 8443. The firewall is configured with App-ID enabled, but traffic to the CRM is being incorrectly identified as 'web-browsing' and 'ssl'. Users are able to access the CRM, but the security team wants to ensure that only authorized users can use this application. They have created a custom App-ID signature based on a unique payload pattern in the first packet. However, after applying the signature and committing, the traffic logs still show the application as 'incomplete' or 'web-browsing'. The firewall is running PAN-OS 10.1. What is the most likely reason the custom App-ID is not working?
⚠ Common exam trap
Many candidates assume a commit immediately updates all traffic, but Palo Alto Networks firewalls only apply App-ID changes to new sessions, not existing ones.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The existing sessions are still using the old identification; new sessions must be initiated to see the correct application.
App-ID identification occurs at session setup. Once a session is established, the application is determined from the first few packets. If the custom App-ID signature was applied after sessions to the CRM were already active, those existing sessions will continue to show the previously identified application (e.g., 'web-browsing' or 'ssl') until they expire. Only new sessions will trigger the new signature and display the correct custom application. This is a fundamental behavior of Palo Alto Networks' session-based architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall needs to have Application Override enabled for the custom signature to work.
Why it's wrong here
Application Override bypasses App-ID signature inspection for specified ports, so it cannot make a custom signature match; it is used deliberately to skip inspection for trusted traffic. The custom App-ID fails because the pattern sits beyond the inspected first packet or the session is already identified.
- ✗
The firewall must be restarted to apply the new custom signature.
Why it's wrong here
Committing the candidate configuration activates custom signatures without a reboot, so restarting changes nothing about App-ID matching. A restart is relevant only for certain software upgrades or low-level system changes, not for loading a newly created signature into the running configuration.
- ✓
The existing sessions are still using the old identification; new sessions must be initiated to see the correct application.
Why this is correct
App-ID identification occurs only at session setup, so existing sessions retain their original verdict of web-browsing or ssl. Because the custom signature was committed after those flows began, the firewall never re-evaluates them. Terminating the current sessions forces new ones, where the payload pattern is matched and the custom App-ID applied.
- ✗
The signature must be imported from the Palo Alto Networks application database.
Why it's wrong here
Custom App-IDs are created locally in the firewall's signature editor and committed; they are not imported from Palo Alto Networks' application database, which only supplies predefined signatures. Importing applies when you need vendor-published App-IDs for known applications rather than a proprietary internal protocol.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.