Courseiva

PCNSE Securing Traffic and App-ID Practice Question

A security administrator is configuring App-ID to distinguish between a sanctioned SaaS application and an unsanctioned one that both use HTTPS on TCP port 443. The administrator wants the firewall to identify the sanctioned application by inspecting the TLS handshake and certificate details. Which firewall feature should be enabled to achieve this?

⚠ Common exam trap

The trap here is assuming that App-ID can identify all HTTPS applications without decryption, when in fact many applications require SSL Forward Proxy decryption to be properly identified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSL Forward Proxy decryption

To differentiate applications that both use HTTPS on port 443, the firewall must decrypt the traffic and inspect the TLS handshake and certificate. SSL Forward Proxy decryption enables this by acting as a man-in-the-middle for outbound connections, allowing App-ID to identify the application based on its unique characteristics. This is the correct approach for identifying sanctioned SaaS applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL Inbound Inspection

    Why it's wrong here

    SSL Inbound Inspection is used to decrypt traffic destined to internal servers, typically for inbound connections from external clients. It requires the server's private key and is not suited for identifying outbound SaaS applications initiated by internal users. The scenario describes outbound traffic to external SaaS, so inbound inspection would not apply.

  • ✗

    App-ID with TLS 1.3 only

    Why it's wrong here

    TLS 1.3 encrypts more of the handshake, including the server certificate, which makes App-ID less effective without decryption. Enabling TLS 1.3 alone does not provide the firewall with the necessary visibility to distinguish between applications. The administrator needs decryption to inspect the certificate and handshake details.

  • ✗

    DNS Sinkhole

    Why it's wrong here

    DNS Sinkhole is a security feature that redirects malicious DNS queries to a sinkhole IP address to block access to known malicious domains. It does not decrypt or inspect TLS traffic and cannot identify applications based on certificate details. This feature is unrelated to the requirement of distinguishing SaaS applications over HTTPS.

  • ✓

    SSL Forward Proxy decryption

    Why this is correct

    SSL Forward Proxy decryption allows the firewall to intercept and decrypt outbound TLS sessions, inspect the ClientHello and server certificate, and apply App-ID to the decrypted traffic. This enables identification of applications that use HTTPS on port 443, such as sanctioned SaaS apps, by examining the actual application payload and certificate attributes rather than just the port.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.