Courseiva
App-ID and Content-ID →mediumMultiple Choice

PCNSA App-ID and Content-ID Practice Question

A security administrator notices that a large number of unknown TCP sessions are being generated by an internal application. The administrator wants to identify the application using App-ID. Which action should they take first?

⚠ Common exam trap

The trap here is jumping to create a custom App-ID based on limited information, when the ACC should be used first to gather details about the unknown application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Application Command Center (ACC) to view unknown applications and their characteristics.

The Application Command Center (ACC) provides detailed visibility into unknown applications, including their traffic patterns and endpoints. By analyzing this information, the administrator can determine if the application is a custom internal tool or a known application that is not yet identified. This is the recommended first step before creating a custom App-ID or contacting support. Other actions like creating a port-based App-ID or enabling logging are not as effective for initial identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable logging on the security policy rule to capture the unknown sessions.

    Why it's wrong here

    Enabling logging can help collect data, but it does not directly identify the application. The administrator needs to analyze the traffic patterns to create a signature. Logging is a step, but not the first action for identification.

  • ✗

    Submit a support ticket to Palo Alto Networks to create a new App-ID.

    Why it's wrong here

    Submitting a support ticket can be done if the application is widely used and should be added to the App-ID database, but it is not the first action. The administrator should first analyze the traffic locally to gather information. Also, this process takes time, so it's not immediate.

  • ✓

    Use the Application Command Center (ACC) to view unknown applications and their characteristics.

    Why this is correct

    The Application Command Center (ACC) provides visibility into unknown applications, showing details such as source, destination, and port. This helps the administrator understand the traffic and decide whether to create a custom App-ID or request a new App-ID from Palo Alto Networks. It is the first step in identifying the application.

  • ✗

    Create a custom App-ID based on the destination port.

    Why it's wrong here

    Creating a custom App-ID based solely on the destination port is not recommended because it lacks unique identification and may cause false positives. The administrator should first analyze the traffic to determine the application's signature. Therefore, this is not the first action.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.