PCNSA App-ID and Content-ID Practice Question
A security administrator is troubleshooting why a custom application is not being identified by App-ID. The application uses a proprietary protocol over TCP and is not recognized. Which two actions can the administrator take to enable App-ID to identify this application? (Choose two.)
⚠ Common exam trap
The trap here is thinking that SSL decryption or URL Filtering can help identify any application, when they are specific to encrypted or web traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom App-ID signature using the Application Objects interface.
To enable App-ID to identify a proprietary application, the administrator can create a custom App-ID signature, which defines patterns for the application, or use Application Override to force traffic to a custom application based on IP and port. Both methods allow the firewall to recognize and control the application. SSL decryption, URL Filtering, and IP/port-based Security rules do not provide application identification for non-web, non-TLS proprietary protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom App-ID signature using the Application Objects interface.
Why this is correct
Creating a custom App-ID signature allows the administrator to define patterns and characteristics for the proprietary application. This is done through the Application Objects interface in PAN-OS, where you can specify protocol, port, and patterns. Once created, the custom App-ID can be used in Security policy rules. This is a valid method to enable identification of applications not recognized by the built-in App-ID database.
- ✗
Enable SSL decryption for the application's traffic.
Why it's wrong here
SSL decryption is used to inspect encrypted traffic, but the proprietary application uses a non-TLS protocol over TCP. Enabling SSL decryption would not help App-ID identify the application because the traffic is not SSL/TLS encrypted. Decryption is irrelevant for this scenario and would not address the identification issue.
- ✗
Configure a URL Filtering profile to categorize the application's traffic.
Why it's wrong here
URL Filtering profiles categorize web traffic based on URLs, which is not applicable to a proprietary TCP-based application. URL Filtering does not assist in identifying non-web applications. It would not enable App-ID to recognize the custom application, as it operates at a different layer and for a different purpose.
- ✓
Use Application Override to force the traffic to a custom application based on port and IP.
Why this is correct
Application Override allows the administrator to force traffic to a specific application based on source/destination IP and port, bypassing App-ID's deep inspection. This can be used as a temporary or permanent solution for applications that App-ID cannot identify. It is particularly useful for proprietary protocols. However, it is less granular than custom App-ID and should be used with caution.
- ✗
Create a Security policy rule to allow the application's IP address and port.
Why it's wrong here
Creating a Security policy rule based on IP and port would allow the traffic but does not enable App-ID to identify the application. The traffic would still be unidentified or identified as unknown-tcp. This does not solve the identification problem; it merely permits the traffic without application visibility.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.