PCNSE Securing Traffic and App-ID Practice Question
A security administrator is configuring App-ID to distinguish between a sanctioned SaaS application and an unsanctioned one that both use HTTPS on TCP port 443. The administrator wants the firewall to identify the sanctioned application by inspecting the TLS handshake and certificate details. Which firewall feature should be enabled to achieve this?
⚠ Common exam trap
The trap here is assuming that App-ID can identify all HTTPS applications without decryption, when in fact many applications require SSL Forward Proxy decryption to be properly identified.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSL Forward Proxy decryption
To differentiate applications that both use HTTPS on port 443, the firewall must decrypt the traffic and inspect the TLS handshake and certificate. SSL Forward Proxy decryption enables this by acting as a man-in-the-middle for outbound connections, allowing App-ID to identify the application based on its unique characteristics. This is the correct approach for identifying sanctioned SaaS applications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSL Inbound Inspection
Why it's wrong here
SSL Inbound Inspection is used to decrypt traffic destined to internal servers, typically for inbound connections from external clients. It requires the server's private key and is not suited for identifying outbound SaaS applications initiated by internal users. The scenario describes outbound traffic to external SaaS, so inbound inspection would not apply.
- ✗
App-ID with TLS 1.3 only
Why it's wrong here
TLS 1.3 encrypts more of the handshake, including the server certificate, which makes App-ID less effective without decryption. Enabling TLS 1.3 alone does not provide the firewall with the necessary visibility to distinguish between applications. The administrator needs decryption to inspect the certificate and handshake details.
- ✗
DNS Sinkhole
Why it's wrong here
DNS Sinkhole is a security feature that redirects malicious DNS queries to a sinkhole IP address to block access to known malicious domains. It does not decrypt or inspect TLS traffic and cannot identify applications based on certificate details. This feature is unrelated to the requirement of distinguishing SaaS applications over HTTPS.
- ✓
SSL Forward Proxy decryption
Why this is correct
SSL Forward Proxy decryption allows the firewall to intercept and decrypt outbound TLS sessions, inspect the ClientHello and server certificate, and apply App-ID to the decrypted traffic. This enables identification of applications that use HTTPS on port 443, such as sanctioned SaaS apps, by examining the actual application payload and certificate attributes rather than just the port.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.