After upgrading PAN-OS from version 9.1 to 10.0, an administrator notices that traffic for an internal custom application is now classified as unknown-tcp instead of the expected custom application. The application was defined using a custom App-ID in the previous version. What is the most likely cause?
Upgrades can change App-ID engine behavior; custom applications may require redefinition.
Why this answer
When upgrading PAN-OS from version 9.1 to 10.0, custom App-IDs defined in the previous version are not automatically compatible because the internal App-ID framework and signature format changed significantly between these major versions. The custom application definition must be re-created or re-imported using the new version's tools, as the old custom App-ID object becomes orphaned or non-functional, causing traffic to fall back to unknown-tcp.
Exam trap
The trap here is that candidates assume custom App-IDs are backward-compatible across major PAN-OS upgrades, when in reality they often require manual re-creation due to changes in the internal App-ID engine and signature format.
How to eliminate wrong answers
Option A is wrong because PAN-OS does not deprecate custom application signatures during an upgrade; deprecation applies only to built-in applications, not user-defined ones. Option C is wrong because an expired license would affect threat prevention, URL filtering, or global protect features, but not the classification of custom App-IDs; App-ID functionality is part of the base firewall license. Option D is wrong because a PAN-OS upgrade does not reset the firewall configuration; configuration is preserved across upgrades unless a factory reset is explicitly performed.