PCNSE Securing Traffic and App-ID Practice Question
A firewall in a high-availability pair shows that App-ID signatures are not syncing between units. Sessions are failing over but application identification is incorrect on the passive unit. What should the administrator verify?
⚠ Common exam trap
Candidates often confuse application override policies (configuration) with App-ID signature updates (content). The question specifically states 'App-ID signatures are not syncing,' which points to content synchronization and licensing, not configuration replication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure both units have the same App-ID license installed.
App-ID signatures are part of the content (App-ID and threat) updates, which require the App-ID license. If both units do not have the same App-ID license installed, the passive unit may lack the necessary signatures, causing incorrect application identification after failover. Verifying that both units have the same license ensures they are eligible to receive the same content updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure both units have the same App-ID license installed.
Why this is correct
Correct. The App-ID license is required to receive App-ID signatures. If the passive unit lacks this license, it won't have the same signatures as the active unit, leading to incorrect App-ID after failover.
- ✗
Configure session distribution for symmetric return.
Why it's wrong here
Incorrect. Session distribution for symmetric return deals with traffic pathing and session ownership in HA, not with App-ID signature synchronization.
- ✗
Verify that application override policies are replicated via HA configuration sync.
Why it's wrong here
Incorrect. Application override policies are configuration objects that map applications to specific ports or data filters; they are not related to the synchronization of App-ID signatures, which are part of content updates.
- ✗
Check that sessions are established on both units.
Why it's wrong here
Incorrect. Sessions being established on both units is a normal HA behavior and does not affect App-ID signature availability.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.