PCNSE Securing Traffic and App-ID Practice Question
A security administrator is troubleshooting why a custom application that uses SSL/TLS on TCP port 9443 is being identified as 'ssl' instead of the custom App-ID. The firewall has a security policy that allows 'ssl' and the custom application. The administrator has already confirmed that the traffic passes through the firewall and that SSL decryption is not enabled. Which action should the administrator take to allow App-ID to correctly identify the application?
⚠ Common exam trap
The trap here is assuming that SSL decryption is always required to identify applications using SSL/TLS, when in fact App-ID can use SSL/TLS fingerprints and custom signatures without decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom App-ID signature for the application using the known SSL/TLS attributes.
When an application uses SSL/TLS and the firewall cannot identify it beyond 'ssl', a custom App-ID signature based on SSL/TLS attributes is the appropriate solution without decryption. This allows the firewall to match the application based on certificate details or other handshake information. Enabling decryption is not necessary and may not be desired. Removing the 'ssl' rule or using dependencies does not address the identification problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SSL decryption on the firewall to inspect the encrypted traffic.
Why it's wrong here
Enabling SSL decryption would allow the firewall to inspect the payload and potentially identify the application, but it is not the recommended first step because it introduces complexity and privacy concerns. The question states that SSL decryption is not enabled, and the goal is to identify the application without decryption. App-ID can identify some applications via SSL/TLS fingerprints and heuristics without decryption, so enabling decryption is not the correct action here.
- ✗
Modify the security policy to allow only the custom application and remove the 'ssl' rule.
Why it's wrong here
Removing the 'ssl' rule would not help App-ID identify the custom application; it would only change the policy enforcement. The firewall still needs to recognize the application to match the custom application rule. The issue is identification, not policy configuration. Without a signature that matches the application's SSL/TLS characteristics, the firewall will continue to classify the traffic as 'ssl' and the custom application rule will not match.
- ✓
Create a custom App-ID signature for the application using the known SSL/TLS attributes.
Why this is correct
Creating a custom App-ID signature is the correct approach when an application uses SSL/TLS and cannot be identified by existing signatures. The administrator can define a custom signature based on SSL/TLS attributes such as server certificate CN, issuer, or other TLS handshake characteristics. This allows the firewall to recognize the application without decrypting traffic, which aligns with the scenario where SSL decryption is not enabled.
- ✗
Configure the firewall to use the 'ssl' application as a dependency for the custom application.
Why it's wrong here
Using 'ssl' as a dependency does not help the firewall identify the custom application. Dependencies are used to enforce that certain applications are allowed before others, but they do not provide identification. The firewall would still see the traffic as 'ssl' and not as the custom application. The administrator needs a way to distinguish the custom application from generic SSL traffic, which requires a custom signature or decryption.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.