Courseiva

PCNSA Policy Evaluation and Management Practice Question

An administrator is configuring a security policy to allow access to a critical application. The application uses multiple protocols and dynamic ports. The administrator wants to ensure that the policy is as secure as possible while allowing legitimate traffic. Which two actions should the administrator take? (Choose two.)

⚠ Common exam trap

The trap here is thinking that dynamic ports require opening all ports or disabling inspection, when App-ID can handle them securely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use App-ID to identify the application and allow only the specific application, rather than allowing the underlying ports.

To securely allow an application with dynamic ports, the administrator should use App-ID to identify the application and create a custom signature if needed. These actions ensure that only the specific application is allowed, regardless of port, while maintaining security. Allowing all ports or disabling inspection would weaken security and are not recommended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the security rule to allow the application based on the destination port only, as dynamic ports are not supported by App-ID.

    Why it's wrong here

    App-ID does support dynamic ports because it identifies applications based on their behavior and payload, not just static ports. Port-based rules are less secure and cannot handle dynamic ports reliably. Using destination port only would not correctly identify the application and could allow unwanted traffic.

  • ✓

    Use App-ID to identify the application and allow only the specific application, rather than allowing the underlying ports.

    Why this is correct

    Using App-ID allows the firewall to identify the application regardless of port or protocol, and to enforce policy based on the actual application. This is more secure than allowing ports because it prevents other applications from using the same ports. It also handles dynamic ports automatically, as App-ID tracks the application's behavior.

  • ✗

    Allow all TCP and UDP ports from the source zone to the destination zone to ensure the application works.

    Why it's wrong here

    Allowing all ports is overly permissive and violates the principle of least privilege. It would allow any application to use any port, greatly increasing the attack surface. This approach is insecure and not recommended, especially for a critical application. The administrator should instead use App-ID or custom signatures.

  • ✓

    Create a custom application signature for the application if it is not recognized by the built-in App-ID database.

    Why this is correct

    If the application is not in the App-ID database, creating a custom signature allows the firewall to identify and control it. This ensures that the policy can match the application specifically, rather than resorting to port-based rules. Custom signatures should be used when predefined signatures are unavailable, to maintain security.

  • ✗

    Disable application inspection for the traffic to improve performance, since the application uses dynamic ports.

    Why it's wrong here

    Disabling application inspection would prevent the firewall from identifying and controlling the application, reducing security. It would also make the policy less effective. Performance should not be prioritized over security in this context. App-ID can handle dynamic ports efficiently without disabling inspection.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.