Courseiva

PCNSA · topic practice

App-ID and Content-ID practice questions

App-ID and Content-ID covers how the firewall classifies traffic and inspects content. For PCNSA, questions test App-ID identification methods, App-ID updates, custom application creation, and using application filters or security policies to control traffic without breaking legitimate business applications.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: App-ID and Content-ID

What the exam tests

What to know about App-ID and Content-ID

Be able to explain how App-ID identifies applications, create or update custom App-IDs for misclassified traffic, and write security policies using application filters that block unwanted traffic while preserving legitimate business applications.

App-ID identification methods including application signatures, protocol decoders, and behavioral heuristics

Creating custom App-ID signatures when traffic is misidentified as ssl or unknown-tcp

Using App-ID updates and reviewing release notes to maintain accurate application identification

Building security policies with application filters to block peer-to-peer traffic while allowing FTP

Watch out for

Common App-ID and Content-ID exam traps

  • ▸Assuming App-ID relies only on port numbers; it also uses signatures, decoders, and heuristics to identify applications.
  • ▸Blocking entire application categories without verifying that legitimate business apps such as FTP are not caught by the rule.
  • ▸Ignoring App-ID update content and release notes, causing applications to become misidentified after signature changes.

Practice set

App-ID and Content-ID questions

20 questions · select your answer, then reveal the explanation

A security engineer is troubleshooting why YouTube video streaming is not being identified as 'youtube-streaming' but instead as 'youtube-base'. What could be the reason?

An organization uses App-ID to allow 'web-browsing' but notices that some web traffic is being blocked. The traffic is HTTP over port 8080. What is a likely cause?

Which two components are part of Content-ID? (Choose two.)

Which THREE factors should be considered when troubleshooting App-ID misidentification? (Choose three.)

Which TWO are capabilities of Content-ID? (Choose two.)

What is the most likely reason the traffic is being denied?

Exhibit

Refer to the exhibit.

Application Command Center
Name: myapp
Category: business-systems
Subcategory: file-sharing
Technology: peer-to-peer
Risk: 4
Characteristics: evasive-behavior, used-by-malware, excessive-bandwidth

Security Policy Rule:
Source: any
Destination: any
Application: myapp
Action: allow
Profile: default

Logs show traffic matching this rule is being denied with action 'reset-both'.

A medium-sized enterprise has deployed a Palo Alto Networks firewall in a branch office. They use App-ID to control access to cloud applications. Recently, they migrated from on-premises Exchange to Office 365. They have a security rule that allows 'office365-base' for all users. However, users report that they cannot access their Office 365 email via Outlook client, although web access works fine. The firewall logs show that the traffic is being allowed as 'office365-base' but no other Office 365 sub-applications are seen. The IT team suspects that App-ID is not fully identifying the Outlook client traffic. What should they do to resolve this issue?

A global company uses a Palo Alto Networks firewall at its headquarters. They have a security policy that allows 'web-browsing' and 'ssl' for all users. Recently, they deployed a new custom web application for internal use that runs on TCP port 8443 with SSL. The application is not identified by App-ID as 'web-browsing' or 'ssl', but as 'unknown-tcp'. The security team wants to ensure that only this specific application is allowed, and all other unknown traffic is blocked. They have created a custom App-ID for the application using application override. However, after applying the override, the traffic is still shown as 'unknown-tcp' in logs. What is the most likely reason?

Drag and drop the steps to configure a URL filtering profile on a Palo Alto Networks firewall into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Match each security zone type to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

External, low trust zone

Internal, high trust zone

Public-facing servers, medium trust

Transparent zone for inline deployments

Which TWO methods can be used to create a custom App-ID signature?

Which TWO are required for accurate application identification when an application uses non-standard ports?

Refer to the exhibit. An administrator sees this output and notices that App-ID is not identifying applications. What is the most likely cause?

Exhibit

show system state | match appid
appid status: init
appid version: 8400-XXXX
appid last update: 2023-01-01

Refer to the exhibit. An administrator notes that traffic to Facebook is being denied. What is the most likely reason?

Exhibit

security rule configuration:
{
  "name": "rule1",
  "from": ["trust"],
  "to": ["untrust"],
  "source": ["any"],
  "destination": ["any"],
  "application": ["web-browsing", "ssl"],
  "action": "allow"
}

Refer to the exhibit. An administrator wants to block all traffic that does not match a specific application (e.g., only allow 'web-browsing'). What should be done?

Exhibit

{
  "rulebase": {
    "security": [
      {
        "name": "allow-all",
        "from": ["trust"],
        "to": ["untrust"],
        "source": ["any"],
        "destination": ["any"],
        "application": ["any"],
        "action": "allow"
      }
    ]
  }
}

A security engineer wants to block downloading of executable files over HTTP and HTTPS, but allow all other web traffic. Which Content-ID feature should be configured to achieve this granular control?

A company's security policy must allow Microsoft Teams traffic but deny all other chat applications. Which type of object should be specified in the 'Application' column of the security policy rule?

A user reports that they cannot download PDF files from a corporate web application. The security policy has a File Blocking Profile applied to deny 'PDF' files. The web application uses 'ssl' and 'web-browsing' apps. What should the administrator verify first?

A Palo Alto Networks firewall is configured with a security rule that allows 'web-browsing' and has a URL Filtering Profile to block 'malware' sites. However, users can still access known malware URLs. What is the most likely cause?

Refer to the exhibit. A user on the Trust zone is trying to download a file from an FTP server on the Untrust zone using FTP on TCP port 21. The firewall's security policy is as shown. What will happen?

Exhibit

Refer to the exhibit.

admin@PA-5000> show running security-policy

Rule Name          Source Zone       Dest Zone        Application            Action
-------            -----------      -----------      -----------            ------
Allow-Web          Trust            Untrust          web-browsing           allow
Allow-SSL          Trust            Untrust          ssl                    allow
Block-FTP          Trust            Untrust          ftp                    deny

admin@PA-5000> show app ftp

application ftp
  description: File Transfer Protocol
  ports: tcp/21
  category: file-sharing
  subcategory: file-protocol
  technology: client-server
  risk: 3
  default: yes

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused App-ID and Content-ID sessions

Start a App-ID and Content-ID only practice session

Every question in these sessions is drawn from the App-ID and Content-ID domain — nothing else.

Related practice questions

Related PCNSA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSA exam test about App-ID and Content-ID?
Be able to explain how App-ID identifies applications, create or update custom App-IDs for misclassified traffic, and write security policies using application filters that block unwanted traffic while preserving legitimate business applications.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just App-ID and Content-ID questions in a focused session?
Yes — the session launcher on this page draws every question from the App-ID and Content-ID domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSA topics?
Use the topic links above to move to related areas, or go back to the PCNSA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSA exam covers. They are not copied from any real exam or dump site.