Courseiva
Securing Traffic and App-ID →mediumMultiple Choice

PCNSE Securing Traffic and App-ID Practice Question

A network security engineer is troubleshooting an application that is inconsistently identified as 'unknown-tcp' in the traffic logs. The application uses TCP port 8080 and initiates with a proprietary binary handshake. The engineer confirms that no custom App-ID has been created. Which action should the engineer take to ensure the firewall reliably identifies this application?

⚠ Common exam trap

The trap here is assuming that allowing the port or enabling decryption will automatically make App-ID recognize a proprietary protocol, when in fact a custom signature is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom App-ID with a signature that matches the proprietary binary handshake and assign it to the application.

The firewall cannot identify a proprietary application if no signature exists. Creating a custom App-ID with a signature that matches the unique binary handshake enables the firewall to classify the traffic correctly based on application-layer attributes, not just port. This ensures consistent policy enforcement and visibility. Other options either bypass identification or misapply features like SSL decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an Application Override policy for port 8080 to force the firewall to treat the traffic as the desired application.

    Why it's wrong here

    Application Override is used to force the firewall to skip App-ID inspection for specific traffic and treat it as a specified application. While it can improve performance, it does not create a signature and may cause the firewall to misclassify other traffic on the same port. This option is wrong because it bypasses App-ID rather than enabling accurate identification, and it does not address the proprietary handshake.

  • ✗

    Enable SSL decryption for all traffic on port 8080 to allow the firewall to inspect the payload.

    Why it's wrong here

    SSL decryption is relevant only for SSL/TLS-encrypted traffic. The scenario describes a proprietary binary handshake, not SSL/TLS. Enabling decryption would not help the firewall recognize a non-SSL protocol and could introduce unnecessary overhead. This option is incorrect because it misdiagnoses the encryption state of the application and does not create a signature for the proprietary handshake.

  • ✗

    Add a security policy rule that allows TCP port 8080 and relies on the firewall's default App-ID for that port.

    Why it's wrong here

    Relying on a port-based rule does not help App-ID identify the application. The firewall's default App-ID for port 8080 may be generic or incorrect, leading to 'unknown-tcp'. Security policies should be application-based, but without a custom signature, the firewall cannot reliably classify the proprietary handshake. This option fails because it does not address the root cause of misidentification.

  • ✓

    Create a custom App-ID with a signature that matches the proprietary binary handshake and assign it to the application.

    Why this is correct

    Creating a custom App-ID with a signature that matches the proprietary handshake allows the firewall to recognize the application based on its unique traffic pattern, not just port. This is the correct approach because App-ID uses deep packet inspection and protocol decoding; a custom signature ensures reliable identification even if the application uses dynamic ports or encryption. The other options do not provide application-layer identification.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.