PCNSE Troubleshoot Practice Question
An administrator is troubleshooting a situation where traffic from a specific application is being dropped by the firewall. The security policy allows the application. The firewall logs show the session is denied, and the reason is 'application mismatch'. What does this indicate?
⚠ Common exam trap
Candidates often assume 'application mismatch' means the application is unknown or unsupported, but it specifically means the traffic was identified as a different application than what the rule expects, highlighting the importance of verifying App-ID results versus rule configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall's App-ID identified the traffic as a different application than the one specified in the rule
The 'application mismatch' log reason indicates that the firewall's App-ID engine identified the traffic as a different application than the one specified in the security rule. Even though the rule allows the application you intended, the actual traffic does not match that App-ID signature, so the session is denied. This is a common scenario when the application classification does not align with the rule's application object.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall's App-ID identified the traffic as a different application than the one specified in the rule
Why this is correct
App-ID inspects the session and identifies the actual application, which may differ from the one the rule specifies. An 'application mismatch' denial means the detected application does not match the rule's application, so the session is dropped. This satisfies the stem's constraint that the policy allows the expected application.
- ✗
The application is not recognized by the firewall and is treated as unknown
Why it's wrong here
Unknown applications are handled by the rule's unknown-tcp, unknown-udp and unknown-p2p settings, producing an 'unknown application' or 'insufficient data' verdict, not application mismatch. Mismatch means the firewall identified a different application than the rule allows. Treating traffic as unknown would be correct when App-ID cannot identify the session.
- ✗
The security rule is not configured to allow any application
Why it's wrong here
An empty application field in the rule means any application is permitted, so it cannot produce an application-mismatch denial. Application mismatch arises when the identified application differs from the one the rule specifies. Leaving the application unset would be correct when the rule should permit all applications regardless of identification.
- ✗
The firewall's SSL decryption is misconfigured
Why it's wrong here
SSL decryption failures produce their own log reasons, such as decryption errors or certificate issues; 'application mismatch' means App-ID identified traffic differing from the policy's expected application. Decryption is tempting because encrypted sessions can hide the true application, but that yields decryption errors, not this specific denial reason.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.