Courseiva

PCNSE Core Concepts and Architecture Practice Question

A security administrator is configuring a firewall to inspect traffic between two internal zones. The administrator wants to ensure that the firewall performs application identification and content inspection on all allowed traffic. Which configuration is required to achieve this?

⚠ Common exam trap

Test-takers frequently confuse SSL decryption with content inspection; decryption is only needed for encrypted traffic, while content inspection requires Security Profiles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a security policy that allows the traffic and attach a Security Profile Group to the policy.

To perform application identification and content inspection on allowed traffic, a security policy must allow the traffic and have a Security Profile Group attached. The Security Profile Group contains the necessary profiles for antivirus, anti-spyware, vulnerability protection, URL filtering, and file blocking. Without these profiles, the firewall only identifies the application but does not inspect the content for threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Decryption policy to forward traffic to a content inspection engine.

    Why it's wrong here

    A Decryption policy is used to define which traffic to decrypt, not to perform content inspection. Content inspection is performed by Security Profiles attached to security policies. Decryption policies alone do not enable content inspection; they only allow the firewall to see inside encrypted sessions, after which security profiles can be applied.

  • ✗

    Create a security policy with the action 'allow' and enable 'Log at Session End'.

    Why it's wrong here

    Enabling 'Log at Session End' only affects logging; it does not enable content inspection. While logging is useful for auditing, it does not provide any inspection capabilities. Content inspection requires Security Profiles to be attached to the security policy, which analyze the traffic for threats and apply actions like blocking or alerting.

  • ✗

    Enable SSL decryption on the firewall for all traffic between the zones.

    Why it's wrong here

    SSL decryption is used to inspect encrypted traffic, but it is not required for application identification and content inspection of unencrypted traffic. The question does not specify that the traffic is encrypted. SSL decryption is an additional step that may be needed for encrypted sessions, but it is not the primary requirement for content inspection of allowed traffic.

  • ✓

    Create a security policy that allows the traffic and attach a Security Profile Group to the policy.

    Why this is correct

    To perform application identification and content inspection, a security policy must be created that allows the traffic and has a Security Profile Group attached. The Security Profile Group includes profiles for antivirus, anti-spyware, vulnerability protection, URL filtering, and file blocking. Without attaching these profiles, the firewall only performs App-ID but not content inspection.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.