Courseiva
Securing Traffic and App-IDhardMultiple ChoiceObjective-mapped

PCNSE Securing Traffic and App-ID Practice Question

A network security engineer is troubleshooting an issue where certain VoIP traffic is being dropped by the firewall. The traffic logs show that the application is identified as 'voip' and the security rule allows 'voip'. However, the traffic is still being dropped. What should the engineer check next?

⚠ Common exam trap

Many exam-takers assume a security rule 'allow' action guarantees traffic passage, overlooking that threat prevention profiles (vulnerability, anti-spyware, etc.) can independently drop traffic after the rule is matched.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check if a vulnerability protection profile is dropping the traffic based on a threat signature.

Even when App-ID correctly identifies the traffic as 'voip' and a security rule allows it, a vulnerability protection profile applied to the rule can still drop the traffic if it matches a threat signature. This is a common scenario where the firewall's threat prevention engine, not the security rule, is responsible for the drop. The engineer should inspect the threat logs for any matching signatures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Confirm that the VoIP protocol is supported by App-ID.

    Why it's wrong here

    The log shows it is identified, so App-ID supports it.

  • Ensure that the security rule action is set to 'allow' and not 'deny'.

    Why it's wrong here

    The logs indicate the rule allows 'voip', so this is not the issue.

  • Verify that the application override is not set for this traffic.

    Why it's wrong here

    Application override would force a different identification, but the log already shows identification as 'voip'.

  • Check if a vulnerability protection profile is dropping the traffic based on a threat signature.

    Why this is correct

    Correct: Security profiles can drop traffic even if the security rule allows the application.

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.