PCNSE Securing Traffic and App-ID Practice Question
A security engineer is configuring a security policy to allow only the specific business application 'salesforce' while blocking all other applications that use HTTPS. The firewall is not performing SSL decryption. What will be the result of the security policy?
⚠ Common exam trap
The trap here is believing that App-ID can identify all applications even when encrypted; in reality, many SaaS applications require decryption to be accurately identified.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy may not work as intended because salesforce traffic will be identified as ssl or web-browsing without decryption.
Without SSL decryption, App-ID cannot see inside the encrypted HTTPS session to identify the specific application. The traffic will be classified as 'ssl' or 'web-browsing', so a policy that allows 'salesforce' will not match. This means the policy will not work as intended, and the engineer must either enable decryption or adjust the policy to account for the limited visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy will allow all HTTPS traffic because salesforce is not identifiable.
Why it's wrong here
If salesforce is not identifiable, the policy rule for salesforce will not match, and the traffic will fall through to subsequent rules. Depending on the rulebase, this could result in a default deny or allow. It is not guaranteed that all HTTPS traffic will be allowed; the outcome depends on the other rules in the policy.
- ✓
The policy may not work as intended because salesforce traffic will be identified as ssl or web-browsing without decryption.
Why this is correct
Without SSL decryption, the firewall cannot inspect the encrypted payload to identify salesforce. The traffic will likely be identified as 'ssl' or 'web-browsing', not 'salesforce'. As a result, the security policy allowing salesforce will not match, and the traffic may be blocked or allowed by other rules, leading to unintended behavior.
- ✗
The policy will correctly allow salesforce and block other HTTPS applications.
Why it's wrong here
Without SSL decryption, the firewall cannot reliably distinguish salesforce from other HTTPS applications because the traffic is encrypted. App-ID may only identify the traffic as 'ssl' or 'web-browsing', not specifically as 'salesforce'. Therefore, the policy will not function as intended and may either block salesforce or allow other applications.
- ✗
The policy will block all HTTPS traffic because salesforce cannot be identified.
Why it's wrong here
If salesforce cannot be identified, the rule allowing salesforce will not match. However, other rules may allow HTTPS traffic. The result is not necessarily a block of all HTTPS traffic; it depends on the rule order and any subsequent rules. The engineer must ensure that the rulebase has an appropriate default deny or allow.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.