Courseiva
App-ID and Content-ID →hardMultiple Choice

PCNSA App-ID and Content-ID Practice Question

An administrator is troubleshooting why an application is being identified as 'incomplete' in the traffic log. What does this indicate?

⚠ Common exam trap

Many exam-takers confuse 'incomplete' with 'unknown' or 'not-applicable', where candidates incorrectly think the firewall simply cannot identify the application, rather than understanding that the session ended before App-ID finished processing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The session was terminated before App-ID could complete.

When App-ID cannot complete its analysis before the session terminates, the traffic log marks the application as 'incomplete'. This typically happens with short-lived sessions or when the firewall receives insufficient data packets to match a signature or decode the protocol. The correct answer is B because App-ID requires multiple packets or a full handshake to definitively identify the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application is using a non-standard port.

    Why it's wrong here

    An 'incomplete' verdict means the firewall saw the session but could not match enough application signatures, typically due to insufficient packets or asymmetric traffic — not the port itself. Non-standard ports are handled by port-independent application identification, so this is tempting when custom ports are suspected, but it does not explain the incomplete state.

  • ✓

    The session was terminated before App-ID could complete.

    Why this is correct

    An 'incomplete' App-ID verdict means the firewall saw too few packets to match a signature, because the session ended early. This satisfies the stem's troubleshooting scenario: the application could not be identified since App-ID never finished its multi-stage inspection before the session closed.

  • ✗

    The firewall could not determine the application.

    Why it's wrong here

    'Incomplete' means the firewall saw the session but could not gather enough packets to identify the application, often due to session termination or insufficient data. It is tempting because it sounds like a failed identification, and would be correct if the log showed 'unknown-tcp' or 'unknown-udp' instead.

  • ✗

    The application is unknown to the firewall.

    Why it's wrong here

    'Unknown' denotes an application the firewall has no signature for; 'incomplete' means identification was attempted but insufficient data was seen. It is tempting because both indicate identification trouble, and would be correct if the log entry read 'unknown-tcp' or 'not-applicable'.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.