PCNSE Securing Traffic and App-ID Practice Question
A security administrator is configuring a security policy to allow the 'web-browsing' application but block the 'facebook' application. The administrator creates a rule that allows 'web-browsing' and a subsequent rule that denies 'facebook'. However, users report that they can still access Facebook. The administrator checks the traffic logs and sees that Facebook traffic is being identified as 'web-browsing'. Which action should the administrator take to correctly block Facebook?
⚠ Common exam trap
The trap here is assuming that App-ID can always identify applications even when encrypted, when in fact SSL decryption is often required for accurate identification of encrypted applications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSL decryption for Facebook traffic to allow App-ID to identify it correctly.
The correct action is to enable SSL decryption for Facebook traffic. Without decryption, the firewall cannot inspect the encrypted payload and may only see generic 'web-browsing' or 'ssl'. By decrypting, the firewall can identify the application as 'facebook' and enforce the deny rule. The other options are either too broad, unreliable, or address a different feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a custom App-ID signature for Facebook based on its SSL certificate.
Why it's wrong here
While a custom signature could identify Facebook based on its SSL certificate, Facebook uses dynamic certificates and content delivery networks, making this unreliable. Additionally, Facebook is already a known application in the App-ID database; the issue is that the firewall is not seeing it due to encryption. A custom signature would not help if the traffic is encrypted and the certificate is not consistent. Decryption is the more reliable solution.
- ✗
Add a URL filtering profile to block facebook.com.
Why it's wrong here
URL filtering can block access to facebook.com, but it is a different feature from App-ID. The question is about App-ID identification and security policy. While URL filtering could be a complementary measure, it does not address the issue of App-ID misidentification. The administrator's goal is to block the application, and the policy is already set to deny 'facebook'; the problem is that the firewall is not identifying it as such. URL filtering would block based on URL, not application, and may not cover all Facebook traffic (e.g., mobile apps).
- ✓
Enable SSL decryption for Facebook traffic to allow App-ID to identify it correctly.
Why this is correct
Facebook uses SSL/TLS encryption, and without decryption, the firewall may only see 'web-browsing' or 'ssl' rather than the specific application. Enabling SSL decryption allows the firewall to inspect the encrypted traffic and identify it as 'facebook'. This is necessary because App-ID cannot always distinguish between encrypted applications without decryption. Once decrypted, the firewall can enforce the deny rule for 'facebook'.
- ✗
Modify the security policy to deny 'ssl' instead of 'facebook'.
Why it's wrong here
Denying 'ssl' would block all SSL traffic, including legitimate business applications, which is too broad. The goal is to block Facebook specifically, not all encrypted traffic. This would cause significant disruption and is not a targeted solution. The administrator should focus on identifying Facebook accurately, which requires decryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.