Courseiva
App-ID and Content-IDeasyMultiple ChoiceObjective-mapped

PCNSA App-ID and Content-ID Practice Question

A security administrator notices that traffic from a custom application is being incorrectly identified as web-browsing. What is the most likely cause?

⚠ Common exam trap

Palo Alto Networks often tests the misconception that an outdated signature database is the root cause, but the trap here is that the custom application has no signature at all, so updating the database would not help—the administrator must create a custom App-ID signature or use an application override.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The custom application uses HTTP but no specific App-ID signature.

When a custom application uses HTTP but lacks a specific App-ID signature, Palo Alto Networks firewalls default to classifying the traffic as web-browsing (HTTP). App-ID relies on a combination of protocol decoders and application signatures; without a custom App-ID signature defined for the application, the firewall cannot distinguish it from generic HTTP traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The application signature database is outdated.

    Why it's wrong here

    An outdated database would cause incorrect identification for many applications, not just custom ones.

  • App-ID is disabled on the security rule.

    Why it's wrong here

    If App-ID were disabled, traffic would appear as 'unknown-tcp' or 'unknown-udp'.

  • The custom application uses HTTP but no specific App-ID signature.

    Why this is correct

    Without a custom signature, App-ID may classify the traffic as web-browsing.

  • Content-ID is blocking the application.

    Why it's wrong here

    Content-ID does not affect application identification; it enforces security policies.

About these practice questions

Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.