PCNSE Deploy and Configure Firewalls Practice Question
A company uses a custom application definition for a proprietary application that runs on UDP port 12345. The security rule allowing the application is configured, but traffic logs show the application as 'unknown' instead of matching the custom app. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume a security rule referencing a custom application will automatically classify all traffic on that rule as the application, but App-ID requires the traffic to match the signature's protocol and port criteria first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic is not matching the app's protocol or port in the signature.
The custom application definition specifies UDP port 12345, but if the actual traffic uses a different port or does not match the protocol (UDP) defined in the signature, the firewall will classify it as 'unknown'. The security rule allows the application, but the traffic must first be identified by the App-ID engine based on the signature's protocol and port criteria; a mismatch here prevents proper classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The custom application signature is not associated with the security rule.
Why it's wrong here
Security rules match applications by name, so no signature association is required; the rule already references the custom app. It is tempting because rule-to-object binding is a familiar troubleshooting step, and would be correct if the rule referenced a different application object than the one defined.
- ✗
The firewall is running in L2 mode.
Why it's wrong here
L2 mode still performs App-ID on transit traffic; the firewall identifies applications regardless of whether interfaces are switched or routed. It is tempting because L2 deployments change how zones and interfaces are configured, and would be correct if the custom application's traffic were being bridged without inspection.
- ✓
The traffic is not matching the app's protocol or port in the signature.
Why this is correct
Custom application signatures match on protocol and port criteria; if the session's UDP port or protocol differs from the signature definition, App-ID cannot identify it, so the session is logged as unknown rather than matching the custom app.
- ✗
The application timeout is too short.
Why it's wrong here
Application timeouts govern session ageing after identification, not whether App-ID matches the signature; a short timeout would cause premature session teardown, not an 'unknown' verdict. It is tempting because timeouts affect long-lived UDP flows, and would be correct if established sessions were being dropped mid-stream.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.