PCNSE Securing Traffic and App-ID Practice Question
A company uses a custom application for internal VoIP traffic. The custom App-ID signature is configured with the correct protocol and port, but traffic is still not matching. The firewall shows the application as 'unknown-tcp'. What should the administrator check next?
⚠ Common exam trap
A common mix-up: candidates assume a custom App-ID only needs correct port/protocol definitions, overlooking that protocol decoders are mandatory for application-layer identification of VoIP and other complex protocols.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure a protocol decoder (e.g., SIP) is enabled for the application.
Custom App-ID signatures require a protocol decoder to inspect application-layer payloads. Even if the port and protocol are correctly defined, without an enabled decoder (e.g., SIP for VoIP), the firewall cannot identify the application and falls back to 'unknown-tcp'. Enabling the appropriate decoder allows the firewall to parse the traffic and match the custom signature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the port range in the custom application is correct.
Why it's wrong here
Port is already configured; dynamic ports may be used.
- ✗
Update the App-ID signature database.
Why it's wrong here
Custom apps do not depend on signature updates.
- ✗
Check for asymmetric routing on the firewall.
Why it's wrong here
Asymmetric routing is less likely for internal traffic.
- ✓
Ensure a protocol decoder (e.g., SIP) is enabled for the application.
Why this is correct
VoIP often uses dynamic ports; a protocol decoder is needed for full identification.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 504-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.