Why Your Custom App-ID Is Not Identifying Traffic: Application Override Required
A company deploys a Palo Alto Networks firewall in a data center. They have a critical application that uses a proprietary protocol over UDP port 12345. The firewall is not correctly identifying the traffic as the custom App-ID they created. They have verified that the custom App-ID is correctly configured and committed. What is the most likely cause?
Quick Answer
The answer is that an application override rule has not been configured to associate the traffic with the custom App-ID. This is the most likely cause because Palo Alto Networks firewalls rely on application signatures and behavioral analysis to identify traffic, and for a proprietary protocol over UDP port 12345, no built-in signature exists to match the custom App-ID. Even when the custom App-ID is correctly configured and committed, the firewall cannot automatically map unknown or proprietary traffic to it; an application override rule explicitly ties the traffic—based on IP, port, or protocol—to the custom App-ID, forcing the firewall to skip signature-based identification. On the PCNSE exam, this scenario tests your understanding that App-IDs are not self-activating for custom protocols, and a common trap is assuming a committed custom App-ID alone is sufficient. A useful memory tip: “Custom App-ID needs a rule to rule—override to override.”
⚠ Common exam trap
Watch out — candidates often assume a correctly configured custom App-ID will automatically identify traffic, but they overlook the need for an Application Override rule to explicitly bind the traffic to that App-ID when the firewall cannot match it via signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An application override rule has not been configured to associate the traffic with the custom App-ID.
The custom App-ID is correctly configured and committed, but the firewall still does not identify the traffic because App-IDs are based on application signatures and behavioral analysis. For a proprietary protocol over UDP, the firewall may not have a signature to match it, so an application override rule is required to explicitly associate the traffic (based on IP, port, or protocol) with the custom App-ID. Without this override, the firewall will continue to treat the traffic as unknown or attempt to match it against built-in App-IDs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firewall must be rebooted for the custom App-ID to take effect.
Why it's wrong here
Committing the configuration is sufficient; reboot is not required.
- ✓
An application override rule has not been configured to associate the traffic with the custom App-ID.
Why this is correct
Application override is required to bypass signature-based identification and assign the custom App-ID.
- ✗
The custom App-ID must be enabled in the 'Applications' section of the firewall settings.
Why it's wrong here
Custom App-IDs are enabled by default once configured.
- ✗
The firewall cannot identify applications over UDP.
Why it's wrong here
App-ID supports UDP application identification.
Go deeper
Related to this question
About these practice questions
One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PCNSE
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses App-ID to identify traffic on their Palo Alto Networks firewall. They notice that a particular application, custom-db-sync, is not being identified correctly. The traffic uses a proprietary protocol over TCP port 4444. The firewall currently has a security rule allowing any application on that port. Which step should the engineer take to enable App-ID to correctly identify custom-db-sync?
medium- ✓ A.Create a custom App-ID for custom-db-sync using the Application Object and define the appropriate signatures.
- B.Enable unknown application identification in the security rule.
- C.Use the default application override for port 4444 to allow traffic.
- D.Change the security rule to use 'application-default' as the service to rely on port-based identification.
Why A: App-ID relies on application signatures to identify traffic, not just port numbers. Since custom-db-sync uses a proprietary protocol over TCP 4444, the firewall cannot match it to any built-in App-ID. Creating a custom App-ID with appropriate signatures (e.g., protocol decoders, pattern matches) allows the firewall to correctly identify this custom application, enabling policy enforcement beyond port-based rules.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.