PCNSA App-ID and Content-ID Practice Question
A security administrator notices that a Security policy rule permitting the application 'ssl' also allows users to access unauthorized SaaS applications that tunnel their traffic inside TLS on TCP 443. The administrator wants to block these applications without disrupting legitimate TLS traffic. Which Palo Alto Networks feature should be used to identify and control these applications?
⚠ Common exam trap
The trap here is assuming that App-ID can identify applications inside encrypted TLS without decryption, or that URL Filtering can see URLs in encrypted traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL Decryption with a Forward Proxy certificate and a Decryption policy
The unauthorized SaaS applications are hidden inside TLS, so App-ID alone cannot see them. SSL Decryption with a Forward Proxy certificate allows the firewall to decrypt the traffic, after which App-ID can identify the actual applications. A Decryption policy determines what to decrypt, and Security policy can then block the specific SaaS applications while allowing legitimate TLS. This combination provides granular control without disrupting all TLS traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
QoS policy to rate-limit traffic on port 443
Why it's wrong here
QoS policies manage bandwidth and prioritization but do not provide application identification or blocking. Rate-limiting all port 443 traffic would affect both legitimate and unauthorized TLS traffic indiscriminately. It cannot selectively block specific SaaS applications, and would degrade performance for allowed services, failing to meet the requirement.
- ✗
Application Override policy to force traffic to a custom application
Why it's wrong here
Application Override can force traffic to a custom application based on port and IP, but it does not decrypt TLS to reveal the actual application inside. It would simply relabel the traffic, not identify the hidden SaaS applications. This does not solve the problem of distinguishing unauthorized applications from legitimate TLS traffic, and may cause unintended blocking if misconfigured.
- ✗
URL Filtering profile to block the SaaS applications by their web categories
Why it's wrong here
URL Filtering operates on HTTP/HTTPS requests and can block based on URL categories, but when traffic is encrypted, the firewall cannot see the URL or category without decryption. The unauthorized SaaS applications tunnel inside TLS, so URL Filtering alone cannot identify them. Thus it would not effectively block these applications while allowing legitimate TLS traffic.
- ✓
SSL Decryption with a Forward Proxy certificate and a Decryption policy
Why this is correct
SSL Decryption with a Forward Proxy certificate allows the firewall to decrypt TLS traffic, enabling App-ID to identify applications tunneled inside SSL. A Decryption policy defines which traffic to decrypt based on URL categories, source/destination, and other criteria. Once decrypted, Security policy rules can block the specific SaaS applications while permitting legitimate TLS traffic, directly addressing the unauthorized access described.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.