PCNSA App-ID and Content-ID Practice Question
A security administrator notices that traffic from a custom application is being incorrectly identified as web-browsing. What is the most likely cause?
⚠ Common exam trap
Palo Alto Networks often tests the misconception that an outdated signature database is the root cause, but the trap here is that the custom application has no signature at all, so updating the database would not help—the administrator must create a custom App-ID signature or use an application override.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The custom application uses HTTP but no specific App-ID signature.
When a custom application uses HTTP but lacks a specific App-ID signature, Palo Alto Networks firewalls default to classifying the traffic as web-browsing (HTTP). App-ID relies on a combination of protocol decoders and application signatures; without a custom App-ID signature defined for the application, the firewall cannot distinguish it from generic HTTP traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The application signature database is outdated.
Why it's wrong here
An outdated signature database would cause unknown or newly released applications to be misclassified, but a custom in-house application has no vendor signature at all, so updating signatures cannot identify it. Signature updates are the right fix when a known commercial application is misidentified after a new release.
- ✗
App-ID is disabled on the security rule.
Why it's wrong here
Disabling App-ID on a security rule stops application identification entirely, so the rule matches on port and protocol; web-browsing runs on ports 80 and 443, which explains the misclassification. It is tempting because disabling App-ID simplifies rule sets, and that is valid when only layer 3/4 filtering is needed.
- ✓
The custom application uses HTTP but no specific App-ID signature.
Why this is correct
Traffic using HTTP without a dedicated App-ID signature falls back to the web-browsing signature, since Palo Alto firewalls identify applications by signature rather than port alone. The custom application therefore matches the generic HTTP decoder, satisfying the stem's constraint of misidentification caused by a missing application signature.
- ✗
Content-ID is blocking the application.
Why it's wrong here
Content-ID blocking prevents traffic; it does not relabel an application as web-browsing. It is tempting because Content-ID inspects payloads and can override App-ID decisions, but blocking produces deny events, not the misidentification described. Content-ID is correct when file or data transfer control is required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.