PCNSA App-ID and Content-ID Practice Question
A security administrator notices that a large number of unknown TCP sessions are being generated by an internal application. The administrator wants to identify the application using App-ID. Which action should they take first?
⚠ Common exam trap
The trap here is jumping to create a custom App-ID based on limited information, when the ACC should be used first to gather details about the unknown application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Application Command Center (ACC) to view unknown applications and their characteristics.
The Application Command Center (ACC) provides detailed visibility into unknown applications, including their traffic patterns and endpoints. By analyzing this information, the administrator can determine if the application is a custom internal tool or a known application that is not yet identified. This is the recommended first step before creating a custom App-ID or contacting support. Other actions like creating a port-based App-ID or enabling logging are not as effective for initial identification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable logging on the security policy rule to capture the unknown sessions.
Why it's wrong here
Enabling logging can help collect data, but it does not directly identify the application. The administrator needs to analyze the traffic patterns to create a signature. Logging is a step, but not the first action for identification.
- ✗
Submit a support ticket to Palo Alto Networks to create a new App-ID.
Why it's wrong here
Submitting a support ticket can be done if the application is widely used and should be added to the App-ID database, but it is not the first action. The administrator should first analyze the traffic locally to gather information. Also, this process takes time, so it's not immediate.
- ✓
Use the Application Command Center (ACC) to view unknown applications and their characteristics.
Why this is correct
The Application Command Center (ACC) provides visibility into unknown applications, showing details such as source, destination, and port. This helps the administrator understand the traffic and decide whether to create a custom App-ID or request a new App-ID from Palo Alto Networks. It is the first step in identifying the application.
- ✗
Create a custom App-ID based on the destination port.
Why it's wrong here
Creating a custom App-ID based solely on the destination port is not recommended because it lacks unique identification and may cause false positives. The administrator should first analyze the traffic to determine the application's signature. Therefore, this is not the first action.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.