Courseiva

PCNSE Core Concepts and Architecture Practice Question

A network engineer is configuring App-ID for a custom application that uses a proprietary protocol over TCP port 12345. The application's traffic is not being identified as expected. Which configuration change should the engineer make to ensure the firewall correctly identifies this application?

⚠ Common exam trap

It's easy for candidates to confuse 'application override' (which disables App-ID) with 'custom application' (which enhances App-ID), leading them to choose option A when they should instead define a new application object with the correct port and signature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define a custom application with the appropriate protocol, port, and optionally a signature.

When a custom application uses a proprietary protocol over a non-standard port, the firewall cannot rely on its built-in App-ID signatures. By defining a custom application object with the correct protocol (TCP), port (12345), and optionally a protocol-level signature (e.g., a byte pattern or sequence), the firewall can accurately identify the traffic. This ensures that App-ID can match the traffic even if the port is not commonly associated with any known application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a security policy rule with an application override to match the port.

    Why it's wrong here

    An application override bypasses App-ID inspection entirely, forcing traffic to a named custom application by port, so the proprietary protocol is never actually identified. It is tempting when App-ID fails, but the correct fix is a custom App-ID signature; overrides suit traffic that must skip inspection.

  • ✓

    Define a custom application with the appropriate protocol, port, and optionally a signature.

    Why this is correct

    App-ID identifies applications by signature and protocol behaviour, not port alone. Since the proprietary protocol runs on a non-standard TCP port, a custom application object must be defined with the correct protocol, port and, where possible, a signature so the firewall can match and classify the traffic correctly.

  • ✗

    Enable SSL decryption on the traffic to inspect encrypted payloads.

    Why it's wrong here

    SSL decryption exposes encrypted payloads for App-ID to inspect, but this proprietary protocol runs in cleartext over TCP 12345, so there is nothing encrypted to decrypt. Decryption is the right choice only when the application's signatures live inside TLS-encrypted traffic that the firewall cannot otherwise read.

  • ✗

    Add the port to the default application's 'port' field in the application object.

    Why it's wrong here

    Editing the default application's port field alters a predefined signature, which App-ID does not use to confirm custom applications; identification relies on protocol signatures and context, not port alone. Port fields suit applications recognised purely by static port, not proprietary protocols needing custom App-ID signatures.

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.