Courseiva
mediumMultiple Select

PCNSA Practice Question: Which TWO of the following are key benefits of…

Which TWO of the following are key benefits of using an Application-Based Security Policy compared to a Port-Based Security Policy? (Choose TWO.)

⚠ Common exam trap

PCNSA often tests the misconception that application-based policies are simpler or faster than port-based policies, when in fact they provide better security and visibility at the cost of additional processing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ability to control applications regardless of port or protocol evasion

Option B is correct because an Application-Based Security Policy identifies traffic by the application signature itself rather than by TCP/UDP port, so it can still enforce policy even when an application uses non-standard ports, tunnels over another protocol, or otherwise attempts port/protocol evasion. Option D is correct because application-based policies natively identify the specific application in use, enabling granular logging, reporting, and auditing of application usage to satisfy compliance requirements. Option A is incorrect because application-based policies are generally more complex to configure than simple port-based rules for well-known protocols like HTTP (TCP 80) and FTP (TCP 21). Option C is incorrect because, while application identification can help with dynamic-port applications, the primary stated benefit is control regardless of port, and port-based policies can also be written to permit dynamic port ranges. Option E is incorrect because application-based inspection typically requires deep packet inspection, which adds processing overhead rather than increasing throughput.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Simpler configuration for traditional protocols like HTTP and FTP

    Why it's wrong here

    While Application-Based Security Policies identify traffic by application signatures and decryption, a Port-Based Policy relies on static L4 port numbers, which HTTP and FTP can easily use without application awareness. This option is tempting because for simple, well-known protocols, a port-based rule is indeed quicker to configure and troubleshoot. However, the question asks for benefits of application-based policy, which provides granular control over application functions—such as blocking specific FTP commands—that port-based rules cannot enforce.

  • ✓

    Ability to control applications regardless of port or protocol evasion

    Why this is correct

    App-ID decodes the payload to identify the application itself, so traffic is matched on true identity rather than TCP/UDP port number. This defeats evasion techniques such as running non-standard applications over ports 80 or 443, satisfying the requirement to control applications irrespective of port or protocol.

  • ✗

    Easier to allow applications that use dynamic ports

    Why it's wrong here

    App-ID identifies the application regardless of the port it uses, so dynamic-port applications are matched without opening wide port ranges. This is a genuine benefit, but the question asks for two, and this option is not among the accepted pair; the expected answers concern application identification and policy granularity rather than dynamic ports specifically.

  • ✓

    Ability to log and report on application usage for compliance

    Why this is correct

    App-ID classification feeds App-Spy and the traffic logs, recording which applications each user or group actually runs. This delivers the granular usage visibility and audit evidence needed to demonstrate compliance, which port-based rules cannot provide since they only report port and protocol.

  • ✗

    Increased throughput because firewall does not need to inspect ports

    Why it's wrong here

    Application-based policies still inspect every packet's ports and payload via App-ID; throughput is governed by firewall processing capacity, not port inspection. It is tempting because port-based rules are coarse, but the correct benefit is identifying applications regardless of port, protocol or evasion technique, not raw performance.

About these practice questions

Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.