Courseiva

PCNSE Core Concepts and Architecture Practice Question

A network security engineer is troubleshooting why a newly installed Palo Alto Networks firewall is not inspecting traffic between two internal subnets. The engineer confirms that the traffic is routed through the firewall, security policies are configured to allow and inspect the traffic, and no drop counters are incrementing. However, the firewall's session table shows sessions in an 'ACTIVE' state but with no application identified. Which component of the Palo Alto Networks Next-Generation Firewall is responsible for identifying the application in this scenario?

⚠ Common exam trap

Candidates often confuse App-ID with Content-ID, as both are 'ID' technologies, but only App-ID identifies the application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

App-ID

App-ID is the Palo Alto Networks technology that identifies applications traversing the firewall. It uses signatures, protocol decoding, and behavioral heuristics to classify traffic accurately. In the scenario, sessions are active but no application is identified, indicating that App-ID has not yet completed its analysis. This could happen if the session is incomplete, if traffic is asymmetric, or if the application is unknown. Once App-ID identifies the application, the firewall can apply the appropriate security policy. The other options are related technologies but do not perform application identification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User-ID

    Why it's wrong here

    User-ID is the technology that maps IP addresses to users and groups, enabling policies based on user identity. It does not identify applications. In this scenario, the problem is application identification, not user mapping. User-ID would be relevant if policies were based on users and the mapping was failing, but the stem specifically mentions that no application is identified. Therefore, User-ID is not the component responsible for application identification.

  • ✓

    App-ID

    Why this is correct

    App-ID is the Palo Alto Networks traffic classification technology that identifies the application regardless of port, protocol, or evasion technique. In this scenario, sessions are active but no application is identified, meaning App-ID has not yet completed its classification. App-ID uses multiple identification mechanisms including application signatures, protocol decoding, and heuristics. Once App-ID identifies the application, it can enforce security policies based on the application. The lack of application identification could be due to incomplete session setup, asymmetric traffic, or insufficient packets for identification.

  • ✗

    Content-ID

    Why it's wrong here

    Content-ID is responsible for inspecting the content of allowed traffic for threats, URLs, and files. It operates after App-ID has identified the application and the security policy allows the session. In this scenario, the issue is that no application is identified, so Content-ID would not yet be engaged. Content-ID includes threat prevention, URL filtering, and file blocking. While Content-ID is critical for security, it is not the component that identifies the application itself.

  • ✗

    SSL Decryption

    Why it's wrong here

    SSL Decryption is a feature that decrypts SSL/TLS traffic to allow App-ID and Content-ID to inspect encrypted sessions. While it can enable application identification for encrypted traffic, it is not the component that performs the identification itself. In this scenario, the traffic might be unencrypted or the issue could be unrelated to encryption. The core component that identifies applications is App-ID, not SSL Decryption. SSL Decryption is an enabler, not the identifier.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.