Courseiva

CCNA Securing Traffic and App-ID Questions

34 questions · Securing Traffic and App-ID · All types, answers revealed

1
MCQmedium

A security engineer is troubleshooting why a web application is not being identified correctly. The firewall shows the session as 'ssl' instead of the specific application. The engineer has verified that the traffic is using TLS 1.3. What is the most likely reason for the misidentification?

A.The application uses a non-standard port.
B.The security policy does not allow the application.
C.SSL decryption is not configured for the traffic.
D.The firewall does not support TLS 1.3 inspection.
AnswerC

Without SSL decryption, the firewall cannot inspect the encrypted payload and can only identify the traffic as ssl based on the port or protocol. To identify the specific application inside TLS, the firewall must decrypt the traffic. This is especially true for TLS 1.3, where more of the handshake is encrypted, making it harder to identify the application without decryption.

Why this answer

SSL decryption is required to inspect encrypted traffic and identify the application inside. Without decryption, the firewall can only classify the session as ssl based on the protocol, not the specific application. This is particularly relevant for TLS 1.3, where more of the handshake is encrypted, making decryption even more critical for accurate App-ID.

Exam trap

The trap here is assuming that App-ID can identify applications inside encrypted traffic without decryption, but encryption hides the application signatures, so only ssl is identified.

2
MCQeasy

A network engineer notices that traffic from an internal user to a web application is being incorrectly identified as 'web-browsing' instead of the custom application 'my-app'. The engineer has already created a custom application 'my-app' with the correct signature. What is the most likely reason for the misidentification?

A.The custom application is not activated in the security policy rule.
B.The application override is not configured.
C.The vulnerability protection profile is dropping the traffic.
D.The decryption policy is blocking the traffic.
AnswerB

Application override forces traffic on specified ports to be treated as the custom application, bypassing standard App-ID signature matching. Without it, the firewall continues classifying the session as web-browsing, so the custom my-app signature never applies to that traffic.

Why this answer

When a custom application is created with a signature, the firewall uses App-ID to identify the traffic based on the signature. However, if the traffic is still being misidentified as 'web-browsing', it means the firewall is matching the default HTTP/HTTPS application before the custom signature can be evaluated. An application override is required to explicitly tell the firewall to skip App-ID processing for that traffic and instead use the custom application 'my-app'.

Without the override, the firewall's default App-ID logic continues to classify the traffic based on its standard signatures.

Exam trap

The trap here is that candidates often think creating a custom application with a signature is sufficient for identification, but they overlook the need for an application override to bypass the default App-ID classification for traffic on standard ports like 80 or 443.

How to eliminate wrong answers

Option A is wrong because the custom application does not need to be 'activated' in a security policy rule; it is automatically available once created and committed, and the issue is about identification, not policy enforcement. Option C is wrong because a vulnerability protection profile drops traffic based on threats, not misidentification; it would not cause the traffic to be seen as 'web-browsing' instead of 'my-app'. Option D is wrong because the decryption policy controls whether traffic is decrypted or not, but it does not affect how App-ID classifies the application; misidentification occurs before decryption decisions are applied.

3
MCQhard

Refer to the exhibit. An administrator notices that HTTPS traffic to a specific website is being denied. What is the most likely cause?

A.The HTTPS traffic is being identified as web-browsing instead of ssl, so it does not match rule 2 and is denied by rule 3.
B.Rule 2 does not have a service set to application-default, so it cannot match the traffic.
C.The traffic is from trust to trust, matching rule 4, but still denied.
D.The traffic requires a specific service other than application-default.
AnswerA

When HTTPS uses no SNI or the firewall cannot inspect it, App-ID classifies the session as web-browsing on port 443 rather than ssl. The rule expecting ssl does not match, so the session falls through to the deny rule, explaining the denial.

Why this answer

When App-ID identifies HTTPS traffic as web-browsing (HTTP over port 443) instead of ssl, the traffic does not match rule 2 (which requires the 'ssl' application). Consequently, it falls through to rule 3, which denies the traffic. This misidentification often occurs when the SSL handshake is incomplete or when decryption is not configured, causing the firewall to classify the traffic based on the port rather than the application signature.

Exam trap

A common trap is to assume that the service setting (application-default) is required for App-ID to match traffic, when the real issue is application misidentification due to incomplete SSL inspection or port-based fallback.

How to eliminate wrong answers

Option B is wrong because rule 2 does not need a service set to application-default; the service setting is used for port-based matching, but App-ID can match applications regardless of the service if the application is correctly identified. Option C is wrong because the traffic is from trust to untrust (as indicated by the exhibit showing source zone trust and destination zone untrust), not trust to trust, so rule 4 does not apply. Option D is wrong because the issue is not about requiring a specific service; the traffic is being denied because App-ID misclassifies it as web-browsing, not because of a missing service definition.

4
MCQmedium

During an audit, it is discovered that some traffic from a legacy application is being incorrectly identified as 'ssl' because the application uses a custom encryption scheme over TCP port 443. The engineer has created a custom application signature that matches the legacy application's handshake. What additional configuration is needed to ensure the legacy application is correctly identified?

A.Create an application override rule to force the identification.
B.Create a security policy rule that explicitly allows the custom application.
C.Change the default port of the custom application from 443 to a different port.
D.Disable SSL decryption for that traffic.
AnswerA

An application override rule forces the firewall to classify matching traffic as the specified custom application, bypassing App-ID's signature-based inspection entirely. Since the legacy application's custom encryption on port 443 causes App-ID to misidentify it as 'ssl', the override satisfies the requirement to correctly identify this traffic by explicitly binding it to the custom signature.

Why this answer

An application override rule forces App-ID to classify traffic based on the custom signature, bypassing the default identification that incorrectly flags the legacy application's custom encryption over TCP 443 as 'ssl'. Without the override, App-ID may still match the traffic to the built-in 'ssl' application due to port-based heuristics, even with a custom signature defined. The override ensures the custom application is applied to the session, overriding any conflicting App-ID results.

Exam trap

The trap here is that candidates assume creating a custom signature alone is sufficient to reclassify traffic, but they overlook that App-ID's port-based heuristics for well-known ports like 443 can override signature matches unless an explicit application override is configured.

How to eliminate wrong answers

Option B is wrong because creating a security policy rule that explicitly allows the custom application does not change how App-ID identifies the traffic; the traffic would still be misidentified as 'ssl' and might be blocked or logged incorrectly. Option C is wrong because changing the default port of the custom application from 443 to a different port does not address the misidentification; the legacy application still uses TCP 443, and App-ID would continue to see the traffic on that port, potentially matching 'ssl' again. Option D is wrong because disabling SSL decryption does not affect App-ID identification; decryption is a separate function that inspects encrypted payloads, but the custom encryption scheme is not SSL/TLS, so decryption would fail or be irrelevant, and the traffic would still be misidentified as 'ssl'.

5
MCQmedium

A security engineer is configuring a security policy to allow only the specific business application 'salesforce' while blocking all other applications that use HTTPS. The firewall is not performing SSL decryption. What will be the result of the security policy?

A.The policy will allow all HTTPS traffic because salesforce is not identifiable.
B.The policy may not work as intended because salesforce traffic will be identified as ssl or web-browsing without decryption.
C.The policy will correctly allow salesforce and block other HTTPS applications.
D.The policy will block all HTTPS traffic because salesforce cannot be identified.
AnswerB

Without SSL decryption, the firewall cannot inspect the encrypted payload to identify salesforce. The traffic will likely be identified as 'ssl' or 'web-browsing', not 'salesforce'. As a result, the security policy allowing salesforce will not match, and the traffic may be blocked or allowed by other rules, leading to unintended behavior.

Why this answer

Without SSL decryption, App-ID cannot see inside the encrypted HTTPS session to identify the specific application. The traffic will be classified as 'ssl' or 'web-browsing', so a policy that allows 'salesforce' will not match. This means the policy will not work as intended, and the engineer must either enable decryption or adjust the policy to account for the limited visibility.

Exam trap

The trap here is believing that App-ID can identify all applications even when encrypted; in reality, many SaaS applications require decryption to be accurately identified.

6
MCQeasy

A security administrator is reviewing traffic logs and notices that a known application is being identified as 'web-browsing' instead of its correct App-ID. The application uses HTTP and is not encrypted. The administrator confirms that the application is not a custom application. What is the most likely cause of this misidentification?

A.The firewall's App-ID database is outdated and does not have the signature for the application.
B.The application's traffic is being tunneled over HTTP and the firewall cannot distinguish it from web-browsing.
C.The application uses standard HTTP and does not have a unique signature, so the firewall defaults to 'web-browsing'.
D.The firewall is configured with an Application Override for HTTP that forces all HTTP traffic to be identified as web-browsing.
AnswerC

If an application uses standard HTTP and does not have a distinct signature, the firewall may identify it as 'web-browsing' because it matches the web-browsing App-ID. This is the correct answer because App-ID relies on unique patterns; without them, the firewall falls back to the generic web-browsing classification. This is a common scenario for applications that are essentially web-based but lack specific signatures.

Why this answer

App-ID identifies applications based on unique traffic patterns. If an application uses standard HTTP and lacks a distinct signature, the firewall may classify it as 'web-browsing' because it matches that generic App-ID. This is the most likely cause in the absence of custom configurations.

Other options involve less probable scenarios like outdated databases or overrides.

Exam trap

The trap here is assuming that all HTTP applications have unique App-ID signatures, when many web-based applications are simply classified as web-browsing.

7
MCQeasy

An administrator needs to create a custom application for a proprietary database protocol that uses TCP port 7890. What is the first step in defining this application in App-ID?

A.Create a new application and define the default port.
B.Create a new application group.
C.Create a new custom application tag.
D.Create a new application filter.
AnswerA

Defining the application object and its default port establishes the App-ID signature's foundation before context, identification, and dependency criteria are added. The port anchors the proprietary protocol so subsequent traffic matching can be built around it.

Why this answer

To create a custom application for a proprietary database protocol using TCP port 7890, the first step is to create a new application and define the default port. In App-ID, custom applications are defined by specifying the application name, the protocol (TCP/UDP), and the default port number, which allows the firewall to identify traffic for that application based on the port. This is the foundational step before any additional properties like timeouts or advanced settings can be configured.

Exam trap

The trap here is that candidates often confuse the order of operations and think they need to first create an application group or tag to organize the custom application, but the actual first step is always to create the application object itself with its default port.

How to eliminate wrong answers

Option B is wrong because an application group is used to logically group multiple applications for policy enforcement, not to define a new application or its port. Option C is wrong because a custom application tag is a label for organizing applications, not a method to define the application itself or its port. Option D is wrong because an application filter is used to select applications based on predefined criteria (e.g., category, technology), not to create a new application with a specific port.

8
MCQeasy

A firewall shows session logs with application 'incomplete' for many SSL connections. Which action should be taken to improve App-ID accuracy?

A.Disable application identification for SSL traffic.
B.Enable HTTP/2 protocol decoding.
C.Enable SSL decryption for the traffic.
D.Allow sessions with application 'incomplete' in policy.
AnswerC

App-ID identifies applications by inspecting payload; encrypted SSL traffic exposes only the certificate and handshake, so sessions remain 'incomplete'. Enabling SSL decryption lets the firewall read the application data and match signatures, improving identification accuracy.

Why this answer

The 'incomplete' application label indicates that the firewall could not fully identify the application because the traffic was encrypted. Enabling SSL decryption allows the firewall to inspect the decrypted payload, which is necessary for App-ID to accurately classify the application. Without decryption, App-ID can only rely on metadata like IP addresses and ports, which is often insufficient for SSL connections.

Exam trap

The trap here is that candidates may think enabling HTTP/2 decoding (Option B) will solve the issue, but HTTP/2 is a transport protocol, not a decryption mechanism; without SSL decryption, the firewall still cannot see the encrypted payload regardless of the HTTP version.

How to eliminate wrong answers

Option A is wrong because disabling application identification for SSL traffic would prevent any App-ID analysis, leaving all SSL sessions as 'incomplete' and defeating the purpose of improving accuracy. Option B is wrong because HTTP/2 protocol decoding is a feature for parsing HTTP/2 traffic, but it does not address the root cause of encryption; without decryption, the firewall still cannot inspect the payload to identify the application. Option D is wrong because allowing sessions with application 'incomplete' in policy does not improve App-ID accuracy; it merely bypasses security controls, leaving the traffic unidentified and potentially risky.

9
MCQmedium

A company uses App-ID to identify traffic on their Palo Alto Networks firewall. They notice that a particular application, custom-db-sync, is not being identified correctly. The traffic uses a proprietary protocol over TCP port 4444. The firewall currently has a security rule allowing any application on that port. Which step should the engineer take to enable App-ID to correctly identify custom-db-sync?

A.Create a custom App-ID for custom-db-sync using the Application Object and define the appropriate signatures.
B.Enable unknown application identification in the security rule.
C.Use the default application override for port 4444 to allow traffic.
D.Change the security rule to use 'application-default' as the service to rely on port-based identification.
AnswerA

Creating a custom App-ID with signatures is the only way App-ID can recognise a proprietary protocol; no built-in decoder exists for it. Because the rule currently permits any application on TCP 4444, the firewall cannot classify the session, so defining the signature in the Application Object satisfies the identification constraint.

Why this answer

App-ID relies on application signatures to identify traffic, not just port numbers. Since custom-db-sync uses a proprietary protocol over TCP 4444, the firewall cannot match it to any built-in App-ID. Creating a custom App-ID with appropriate signatures (e.g., protocol decoders, pattern matches) allows the firewall to correctly identify this custom application, enabling policy enforcement beyond port-based rules.

Exam trap

The trap here is that candidates often confuse 'application override' (which bypasses App-ID) with 'custom App-ID' (which enhances App-ID), leading them to choose option C, thinking it will force identification when it actually disables App-ID for that traffic.

How to eliminate wrong answers

Option B is wrong because enabling unknown application identification only allows the firewall to treat unidentified traffic as 'unknown-tcp' or 'unknown-udp', but it does not create a specific signature to identify custom-db-sync; the traffic would still not be recognized as that custom application. Option C is wrong because an application override bypasses App-ID entirely, forcing the firewall to treat all traffic on port 4444 as a specified application, which defeats the purpose of using App-ID to correctly identify the custom protocol. Option D is wrong because using 'application-default' as the service only changes the port binding to the default port for the identified application, but since custom-db-sync is not identified at all, this action does not enable its recognition; App-ID must first identify the application before 'application-default' can be relevant.

10
MCQmedium

A security administrator is configuring an outbound security policy for a new SaaS application. The application uses multiple dynamic ports and occasionally changes its server IPs. The administrator wants to allow only this application while blocking all other traffic on those ports. Which Palo Alto Networks feature should be used to identify and control this application?

A.Service objects with TCP port ranges in the security policy
B.App-ID with application filters in the security policy
C.External Dynamic Lists (EDLs) with IP addresses of the SaaS provider
D.URL filtering profiles with custom URL categories
AnswerB

App-ID identifies the application regardless of port or IP, and application filters allow grouping applications by characteristics such as category, subcategory, technology, and risk. This enables precise control over the SaaS application while blocking others, even with dynamic ports and changing IPs. App-ID is the core technology for application-based policy enforcement on Palo Alto Networks firewalls.

Why this answer

App-ID with application filters allows the firewall to identify the SaaS application by its unique traffic characteristics, not by port or IP. This ensures that only the desired application is allowed, even when it uses dynamic ports or changes IP addresses. Application filters further refine policy by grouping applications based on attributes like category and risk, providing granular control.

Exam trap

The trap here is assuming that a port-based service object or IP-based EDL can reliably control an application that uses dynamic ports and changing IPs, but only App-ID can identify the application regardless of those factors.

11
Drag & Dropmedium

Order the steps to upgrade the PAN-OS software on a standalone firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for upgrading PAN-OS on a standalone firewall is: Download the new image from the support portal, Upload it to the firewall, Install the image, Reboot the firewall to load the new version, and Verify the upgrade was successful. Common mistakes include swapping the order of upload and download, installing before upload, or reboot before install.

12
MCQhard

An organization has two different applications (AppA and AppB) that both use TCP port 8080. The firewall must apply different security policies to each application. What is the recommended approach?

A.Use source/destination IP addresses in security policies instead of App-ID.
B.Add the applications on separate virtual wire interfaces.
C.Change the port of one application to a different value.
D.Create an application override policy to identify each application by IP address.
AnswerD

Application override lets the firewall classify AppA and AppB by source or destination IP rather than signature, since both share TCP port 8080 and App-ID cannot distinguish them. This satisfies the requirement to apply different security policies to each application.

Why this answer

When two applications share the same TCP port (8080), App-ID cannot differentiate them based on port alone. An application override policy allows you to explicitly identify each application by its source/destination IP address, overriding the default App-ID classification and enabling separate security policies for AppA and AppB.

Exam trap

The trap here is that candidates often assume App-ID can always distinguish applications on the same port, but in reality, when applications share the same port and protocol, an application override is required to enforce different policies based on IP addresses.

How to eliminate wrong answers

Option A is wrong because using source/destination IP addresses in security policies without App-ID bypasses the application visibility and control that App-ID provides, and it does not leverage the firewall's ability to identify applications by their behavior. Option B is wrong because virtual wire interfaces are used for transparent mode deployments and do not solve the problem of distinguishing two applications on the same port; they would still see the same TCP port 8080 traffic. Option C is wrong because changing the port of one application is a workaround that may not be feasible in production and does not utilize the firewall's App-ID capabilities; it also introduces unnecessary complexity and potential compatibility issues.

13
MCQhard

A security administrator is troubleshooting App-ID on a firewall that is deployed in a Layer 2 transparent mode. The administrator notices that some applications are not being identified correctly, even though the traffic is not encrypted. What is the most likely reason for this issue?

A.App-ID requires the firewall to be in Layer 3 mode to perform protocol decoding.
B.Layer 2 transparent mode does not support App-ID inspection.
C.The firewall is not in the path of the traffic, so it cannot inspect it.
D.The firewall may be configured to bypass App-ID inspection for certain zones or interfaces.
AnswerD

In Layer 2 transparent mode, the firewall can be configured with zones and interfaces that have App-ID inspection disabled or bypassed, such as when using a 'tap' mode or when certain traffic is excluded. This can prevent App-ID from identifying applications. The administrator should check the zone and interface configurations to ensure App-ID is enabled.

Why this answer

In Layer 2 transparent mode, the firewall can inspect traffic, but App-ID may be bypassed if certain zones or interfaces are configured to disable inspection. This can happen if the administrator has set the zone to not perform App-ID or if the traffic is excluded from inspection. Checking these configurations is the most likely solution.

Exam trap

The trap here is assuming that Layer 2 mode inherently prevents App-ID inspection, when in fact it is supported, but configuration can disable it.

14
MCQmedium

Refer to the exhibit. A firewall administrator is troubleshooting why some applications are not being correctly identified. The firewall is running App-ID version 8000-7120. What does the 'appid packet buffer: 1024 KB' indicate?

A.App-ID can only handle 1024 KB of packet data per session.
B.The firewall can buffer up to 1024 KB of packet data for App-ID analysis.
C.The firewall logs the first 1024 KB of every session for App-ID.
D.The firewall offloads App-ID processing to a dedicated buffer of 1024 KB.
AnswerB

The packet buffer figure defines how much packet payload the App-ID engine can hold in memory while matching signatures across multiple packets. Exceeding this 1024 KB limit truncates analysis, causing applications needing deeper inspection to be misidentified.

Why this answer

The 'appid packet buffer: 1024 KB' indicates the maximum amount of packet payload data the firewall can buffer per session for App-ID analysis. This buffer stores the initial packets of a session so that App-ID can inspect the payload for application signatures, even if the data arrives in multiple packets. Option B correctly states this buffering capability.

Exam trap

The trap here is confusing the buffer size with a per-session data limit or a logging threshold, when in fact it is a temporary storage mechanism for App-ID analysis.

How to eliminate wrong answers

Option A is wrong because App-ID does not have a hard limit of 1024 KB of packet data per session; the buffer size is a configurable limit for buffering, not a processing limit. Option C is wrong because the firewall does not log the first 1024 KB of every session; it buffers the data for analysis, not for logging purposes. Option D is wrong because App-ID processing is not offloaded to a dedicated buffer; the buffer is part of the firewall's normal packet processing pipeline and is used for temporary storage during signature matching.

15
MCQhard

A security administrator is configuring a security policy to allow the 'web-browsing' application but block the 'facebook' application. The administrator creates a rule that allows 'web-browsing' and a subsequent rule that denies 'facebook'. However, users report that they can still access Facebook. The administrator checks the traffic logs and sees that Facebook traffic is being identified as 'web-browsing'. Which action should the administrator take to correctly block Facebook?

A.Create a custom App-ID signature for Facebook based on its SSL certificate.
B.Add a URL filtering profile to block facebook.com.
C.Enable SSL decryption for Facebook traffic to allow App-ID to identify it correctly.
D.Modify the security policy to deny 'ssl' instead of 'facebook'.
AnswerC

Facebook uses SSL/TLS encryption, and without decryption, the firewall may only see 'web-browsing' or 'ssl' rather than the specific application. Enabling SSL decryption allows the firewall to inspect the encrypted traffic and identify it as 'facebook'. This is necessary because App-ID cannot always distinguish between encrypted applications without decryption. Once decrypted, the firewall can enforce the deny rule for 'facebook'.

Why this answer

The correct action is to enable SSL decryption for Facebook traffic. Without decryption, the firewall cannot inspect the encrypted payload and may only see generic 'web-browsing' or 'ssl'. By decrypting, the firewall can identify the application as 'facebook' and enforce the deny rule.

The other options are either too broad, unreliable, or address a different feature.

Exam trap

The trap here is assuming that App-ID can always identify applications even when encrypted, when in fact SSL decryption is often required for accurate identification of encrypted applications.

16
MCQhard

During a security audit, it is discovered that some HTTP traffic is being incorrectly identified as 'web-browsing' instead of 'ssl' even though the traffic uses HTTPS. The firewall is positioned as a transparent bridge and no SSL decryption is configured. What is the most likely cause?

A.SSL decryption must be enabled for the firewall to correctly identify SSL traffic.
B.The firewall is not seeing the full SSL handshake due to asymmetric routing.
C.The default interzone rule is blocking the SSL identification packets.
D.The security policy allows 'web-browsing' before 'ssl' in the rule order.
AnswerB

A transparent bridge without decryption must infer the application from the TLS handshake. With asymmetric routing, return traffic bypasses the firewall, so it never observes the full handshake and falls back to classifying the flow as web-browsing on port 443 instead of ssl.

Why this answer

When a firewall operates as a transparent bridge without SSL decryption, it relies on the Server Name Indication (SNI) field or the certificate exchange during the TLS handshake to identify HTTPS traffic as 'ssl'. Asymmetric routing causes the firewall to see only one direction of the TCP handshake (e.g., only the SYN or only the SYN-ACK), preventing it from observing the full TLS handshake. Without the complete handshake, App-ID cannot extract the necessary signatures (e.g., TLS version, cipher suites, certificate details) and falls back to classifying the traffic as 'web-browsing' based on port 443.

Exam trap

The trap here is that candidates assume SSL decryption is mandatory for SSL identification, but the firewall can identify HTTPS without decryption by inspecting the TLS handshake; the real issue is that asymmetric routing prevents the firewall from seeing the complete handshake, causing App-ID to fall back to port-based classification.

How to eliminate wrong answers

Option A is wrong because SSL decryption is not required for App-ID to identify SSL traffic; the firewall can identify HTTPS by inspecting the TLS handshake metadata (e.g., SNI, certificate) without decrypting the payload. Option C is wrong because interzone rules control traffic flow between zones, not the identification process; App-ID operates before policy enforcement, so a default interzone rule would not prevent the firewall from seeing the SSL handshake packets. Option D is wrong because security policy rule order affects which action is taken on traffic, not how App-ID classifies it; App-ID identifies the application first, then matches it against the policy, so rule order does not cause misidentification.

17
MCQmedium

A company has an application signature for an internal ERP system that uses a proprietary protocol over TCP port 4444. The ERP traffic is sometimes misidentified as unknown-tcp. Which App-ID mechanism should be used to improve identification without affecting the default App-ID engine?

A.Configure a port-based application override for port 4444.
B.Enable SSL decryption for the ERP traffic.
C.Create a custom application with a data pattern (signature).
D.Create an application override to allow the traffic without App-ID.
AnswerC

A custom application with a data pattern matches the proprietary protocol's payload signature on port 4444, giving deterministic identification. This adds a signature without altering the predefined App-ID engine, satisfying the constraint of not affecting default identification.

Why this answer

Creating a custom application with a data pattern (signature) allows the firewall to identify the ERP traffic based on its unique payload characteristics, without overriding or disabling the default App-ID engine. This approach uses a custom App-ID signature that matches the proprietary protocol's data pattern, ensuring accurate identification while the default engine continues to process other traffic normally.

Exam trap

The trap here is that candidates confuse 'application override' (which bypasses App-ID) with 'custom application signature' (which enhances App-ID), leading them to choose options that disable inspection rather than improve it.

How to eliminate wrong answers

Option A is wrong because a port-based application override statically maps all traffic on TCP 4444 to a specific application, which bypasses the default App-ID engine entirely and prevents it from learning or updating signatures for that port. Option B is wrong because SSL decryption is irrelevant for a proprietary protocol over TCP that does not use SSL/TLS encryption; it would not help identify the application and could introduce unnecessary overhead. Option D is wrong because an application override allows traffic without any App-ID inspection, which defeats the purpose of improving identification and can permit unwanted or malicious traffic to pass unchecked.

18
Multi-Selecteasy

Which TWO settings must be configured in a security policy rule to ensure the rule only matches when a specific application is detected on its standard port?

Select 2 answers
A.Set the Source Zone and Destination Zone.
B.Enable Threat Prevention.
C.Set the Service to 'application-default'.
D.Configure Logging at session start.
E.Set the Application to the specific application.
AnswersC, E

Setting Service to 'application-default' restricts the rule to the application's standard ports as defined in its signature, rather than any port. Combined with an explicit application match, this satisfies the requirement that the rule only match when the application is detected on its standard port.

Why this answer

Option E is correct because a security policy rule in PAN-OS matches traffic based on the Application field, so setting it to the specific application ensures the rule only matches sessions where that application is positively identified by App-ID. Option C is correct because setting the Service to 'application-default' makes the rule honor the application's standard/default port(s) as defined by the App-ID signature, rather than a custom or any service, which is exactly what is needed to match the application on its standard port. Together, Application = specific app plus Service = application-default ensures the rule matches only when that application is detected on its default port.

Option A is not required for this specific matching condition, since zones define the source/destination context but do not restrict matching to a detected application on its standard port. Option B (Threat Prevention) is a security profile action applied after matching, not a matching criterion. Option D (Logging at session start) affects logging behavior, not whether the rule matches the application on its standard port.

Exam trap

PCNSE often tests the confusion between Service and Application fields, tempting candidates to think specifying the application alone is sufficient — but without application-default, the rule may match on any port or fail to match the standard port correctly.

19
MCQmedium

A network engineer wants to reduce the number of applications in security policies by combining several applications that are always used together. What is the best practice?

A.Use a wildcard application for the protocol.
B.Create a custom application that covers all the applications.
C.Configure an application group and add all related applications.
D.Remove the individual applications and just use port-based rules.
AnswerC

An application group bundles related applications into one object referenced by policy, reducing rule count while preserving App-ID granularity. This satisfies the requirement to combine applications always used together without listing each separately in every rule.

Why this answer

An application group in Palo Alto Networks PAN-OS allows multiple applications to be referenced as a single object in security policies, reducing policy count while maintaining application-level visibility and control. This is the recommended best practice because it preserves the granular security benefits of App-ID without creating redundant rules. Unlike custom applications, application groups do not require reverse-engineering or signature creation, and they remain dynamically updated with the application content database.

Exam trap

PCNSE often tests the difference between application groups and custom applications, and candidates may incorrectly think a custom application is needed to combine multiple applications. The trap is confusing 'grouping' with 'creating'—application groups are the correct object for aggregation, not custom signatures.

How to eliminate wrong answers

Option A is wrong because a wildcard application (e.g., 'any') for a protocol would match all applications using that protocol, drastically expanding the attack surface and defeating the purpose of application-based policies. Option B is wrong because creating a custom application to cover multiple existing applications is unnecessary and error-prone; custom applications are intended for proprietary or unknown traffic, not for grouping known applications. Option D is wrong because port-based rules abandon application identification entirely, reverting to legacy firewall behavior and losing the security and visibility benefits of App-ID.

20
MCQmedium

An engineer wants to block the use of file-sharing application BitTorrent, but allow file transfers over SFTP which also uses port 22. What is the most effective way to achieve this using App-ID?

A.Create an application filter that matches sftp.
B.Use QoS to limit BitTorrent traffic.
C.Use an application override to classify all port 22 traffic as sftp.
D.Create a security rule that denies application 'bittorrent' and allows application 'sftp'.
AnswerD

App-ID classifies by application signature, not port, so a single rule can deny bittorrent while allowing sftp even though both may traverse port 22. This satisfies the requirement to block BitTorrent without disrupting legitimate SFTP transfers.

Why this answer

D is correct because App-ID identifies applications by their unique signatures, not just ports. By creating a security rule that denies 'bittorrent' and allows 'sftp', the firewall can block BitTorrent traffic even if it uses non-standard ports, while permitting SFTP on port 22 based on its distinct application signature.

Exam trap

The trap here is that candidates assume port-based rules are sufficient, but App-ID is designed to identify applications by their unique signatures, not ports, so a port-based approach (like an application override) would fail to block BitTorrent if it uses the same port as SFTP.

How to eliminate wrong answers

Option A is wrong because an application filter that matches 'sftp' would only allow SFTP traffic but would not block BitTorrent; it does not deny the unwanted application. Option B is wrong because QoS only prioritizes or limits bandwidth for BitTorrent traffic, it does not block it, leaving the application accessible. Option C is wrong because an application override forces all port 22 traffic to be classified as 'sftp', which would incorrectly allow BitTorrent if it also uses port 22, defeating the purpose of blocking it.

21
MCQeasy

A security administrator is configuring App-ID to distinguish between a sanctioned SaaS application and an unsanctioned one that both use HTTPS on TCP port 443. The administrator wants the firewall to identify the sanctioned application by inspecting the TLS handshake and certificate details. Which firewall feature should be enabled to achieve this?

A.SSL Inbound Inspection
B.App-ID with TLS 1.3 only
C.DNS Sinkhole
D.SSL Forward Proxy decryption
AnswerD

SSL Forward Proxy decryption allows the firewall to intercept and decrypt outbound TLS sessions, inspect the ClientHello and server certificate, and apply App-ID to the decrypted traffic. This enables identification of applications that use HTTPS on port 443, such as sanctioned SaaS apps, by examining the actual application payload and certificate attributes rather than just the port.

Why this answer

To differentiate applications that both use HTTPS on port 443, the firewall must decrypt the traffic and inspect the TLS handshake and certificate. SSL Forward Proxy decryption enables this by acting as a man-in-the-middle for outbound connections, allowing App-ID to identify the application based on its unique characteristics. This is the correct approach for identifying sanctioned SaaS applications.

Exam trap

The trap here is assuming that App-ID can identify all HTTPS applications without decryption, when in fact many applications require SSL Forward Proxy decryption to be properly identified.

22
MCQmedium

A security administrator is troubleshooting why a custom application that uses SSL/TLS on TCP port 9443 is being identified as 'ssl' instead of the custom App-ID. The firewall has a security policy that allows 'ssl' and the custom application. The administrator has already confirmed that the traffic passes through the firewall and that SSL decryption is not enabled. Which action should the administrator take to allow App-ID to correctly identify the application?

A.Enable SSL decryption on the firewall to inspect the encrypted traffic.
B.Modify the security policy to allow only the custom application and remove the 'ssl' rule.
C.Create a custom App-ID signature for the application using the known SSL/TLS attributes.
D.Configure the firewall to use the 'ssl' application as a dependency for the custom application.
AnswerC

Creating a custom App-ID signature is the correct approach when an application uses SSL/TLS and cannot be identified by existing signatures. The administrator can define a custom signature based on SSL/TLS attributes such as server certificate CN, issuer, or other TLS handshake characteristics. This allows the firewall to recognize the application without decrypting traffic, which aligns with the scenario where SSL decryption is not enabled.

Why this answer

When an application uses SSL/TLS and the firewall cannot identify it beyond 'ssl', a custom App-ID signature based on SSL/TLS attributes is the appropriate solution without decryption. This allows the firewall to match the application based on certificate details or other handshake information. Enabling decryption is not necessary and may not be desired.

Removing the 'ssl' rule or using dependencies does not address the identification problem.

Exam trap

The trap here is assuming that SSL decryption is always required to identify applications using SSL/TLS, when in fact App-ID can use SSL/TLS fingerprints and custom signatures without decryption.

23
MCQhard

A company deploys a Palo Alto Networks firewall in a data center. They have a critical application that uses a proprietary protocol over UDP port 12345. The firewall is not correctly identifying the traffic as the custom App-ID they created. They have verified that the custom App-ID is correctly configured and committed. What is the most likely cause?

A.The firewall must be rebooted for the custom App-ID to take effect.
B.An application override rule has not been configured to associate the traffic with the custom App-ID.
C.The custom App-ID must be enabled in the 'Applications' section of the firewall settings.
D.The firewall cannot identify applications over UDP.
AnswerB

Application override is required to bypass signature-based identification and assign the custom App-ID.

Why this answer

The custom App-ID is correctly configured and committed, but the firewall still does not identify the traffic because App-IDs are based on application signatures and behavioral analysis. For a proprietary protocol over UDP, the firewall may not have a signature to match it, so an application override rule is required to explicitly associate the traffic (based on IP, port, or protocol) with the custom App-ID. Without this override, the firewall will continue to treat the traffic as unknown or attempt to match it against built-in App-IDs.

Exam trap

The trap here is that candidates assume a correctly configured custom App-ID will automatically identify traffic, but they overlook the need for an Application Override rule to explicitly bind the traffic to that App-ID when the firewall cannot match it via signatures.

How to eliminate wrong answers

Option A is wrong because rebooting the firewall is unnecessary; custom App-IDs take effect immediately after commit, not requiring a reboot. Option C is wrong because custom App-IDs are not enabled in a separate 'Applications' section; they are created and applied via Security policy rules or Application Override rules. Option D is wrong because Palo Alto Networks firewalls can identify applications over UDP; App-ID supports both TCP and UDP protocols, and the issue is specifically about the lack of a signature for this proprietary protocol.

24
Drag & Dropmedium

Order the steps to configure a security policy allowing HTTP traffic from the inside to the outside zone.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Configuring a security policy on Palo Alto Networks firewalls involves defining the traffic flow by specifying source and destination zones, then selecting the application and service, setting the action (allow or deny), and finally committing the changes. The correct order ensures logical consistency and proper policy enforcement. Common mistakes include swapping zones, setting action before application, or placing destination after application.

25
Multi-Selectmedium

An engineer is configuring App-ID for a network that uses both standard and custom applications. Which of the following are best practices for using App-ID effectively? (Choose three.)

Select 3 answers
A.Rely solely on default application signatures for all traffic identification.
B.Use application filters to create dynamic application groups based on characteristics.
C.Use application groups to simplify policy management for related applications.
D.Disable App-ID for traffic on well-known ports to reduce processing overhead.
E.Regularly update Application and Threats content to keep signatures current.
AnswersB, C, E

Application filters group applications dynamically by shared characteristics such as category, risk, or technology, so policy automatically includes new or custom applications matching those traits. This satisfies the scenario's need to manage both standard and custom applications without manually updating static groups whenever custom App-IDs are added.

Why this answer

Option B is correct because application filters let you build dynamic application groups that automatically match applications by characteristics such as category, subcategory, technology, risk, or behavioral attributes, so the group stays current as new App-IDs are added without manual edits. Option C is correct because application groups bundle related applications (for example, business apps or sanctioned SaaS) into a single object referenced in security policy, which simplifies rule management and reduces policy sprawl while still enforcing App-ID per application. Option E is correct because App-ID identification depends on the Application and Threats content database; regularly updating it ensures signatures for new and evolving applications, including custom and evasive apps, are available so the firewall can correctly identify and control traffic.

Option A is not a best practice because relying solely on default signatures ignores custom applications and the need for custom App-ID signatures, application filters, and groups to handle organization-specific traffic. Option D is not a best practice because App-ID should not be disabled on well-known ports; attackers and applications commonly use ports like 80 and 443 for non-standard traffic, and App-ID is designed to inspect and identify applications regardless of port, so disabling it would weaken security.

Exam trap

The trap here is that candidates may think disabling App-ID on well-known ports reduces overhead (Option D), but App-ID is designed to identify applications irrespective of port, and disabling it creates a security gap that attackers can exploit via port hopping.

26
MCQmedium

A network security engineer is troubleshooting an application that is inconsistently identified as 'unknown-tcp' in the traffic logs. The application uses TCP port 8080 and initiates with a proprietary binary handshake. The engineer confirms that no custom App-ID has been created. Which action should the engineer take to ensure the firewall reliably identifies this application?

A.Configure an Application Override policy for port 8080 to force the firewall to treat the traffic as the desired application.
B.Enable SSL decryption for all traffic on port 8080 to allow the firewall to inspect the payload.
C.Add a security policy rule that allows TCP port 8080 and relies on the firewall's default App-ID for that port.
D.Create a custom App-ID with a signature that matches the proprietary binary handshake and assign it to the application.
AnswerD

Creating a custom App-ID with a signature that matches the proprietary handshake allows the firewall to recognize the application based on its unique traffic pattern, not just port. This is the correct approach because App-ID uses deep packet inspection and protocol decoding; a custom signature ensures reliable identification even if the application uses dynamic ports or encryption. The other options do not provide application-layer identification.

Why this answer

The firewall cannot identify a proprietary application if no signature exists. Creating a custom App-ID with a signature that matches the unique binary handshake enables the firewall to classify the traffic correctly based on application-layer attributes, not just port. This ensures consistent policy enforcement and visibility.

Other options either bypass identification or misapply features like SSL decryption.

Exam trap

The trap here is assuming that allowing the port or enabling decryption will automatically make App-ID recognize a proprietary protocol, when in fact a custom signature is required.

27
Multi-Selectmedium

Which TWO factors can cause traffic to be classified as 'incomplete' by App-ID? (Choose two.)

Select 2 answers
A.SSL decryption is not enabled for the session.
B.The firewall CPU is too slow to process packets.
C.The content-ID engine has not been licensed.
D.Asymmetric routing where the firewall sees only one direction of traffic.
E.A deny rule that blocks the traffic.
AnswersA, D

Without SSL decryption, the firewall cannot inspect the encrypted payload, so App-ID identifies only the outer protocol and cannot confirm the true application. The session remains incomplete until sufficient context is available, which decryption would otherwise supply.

Why this answer

Option A is correct because App-ID relies on inspecting the application payload to identify the application; when SSL decryption is not enabled, the firewall only sees encrypted traffic and cannot match a signature, so the session is reported as incomplete (ssl or insufficient-data). Option D is correct because App-ID requires seeing both directions of a flow to correlate client-to-server and server-to-client data; with asymmetric routing the firewall only observes one half of the session, so it cannot complete identification and marks the traffic incomplete. Option B is not correct because a slow CPU causes performance degradation or dropped packets, not an 'incomplete' App-ID classification.

Option C is not correct because Content-ID licensing affects threat, URL, and file inspection, not the base App-ID engine that classifies applications. Option E is not correct because a deny rule simply blocks the session; it does not produce an incomplete App-ID result.

Exam trap

The trap here is that candidates often confuse 'incomplete' with 'blocked' or 'error' states, assuming a slow CPU or licensing issue would cause incomplete classification, when in fact incomplete specifically means the firewall lacks sufficient traffic data to identify the application.

28
Multi-Selecteasy

Which TWO are best practices when configuring App-ID for a production environment? (Choose two.)

Select 2 answers
A.Disable App-ID for traffic that does not match any known application to improve performance.
B.Configure all security policies based on port only for consistency.
C.Use applications instead of ports in security policies.
D.Enable security profiles (e.g., vulnerability protection) along with App-ID.
E.Limit application usage to only well-known applications to reduce attack surface.
AnswersC, D

App-ID identifies applications by signature regardless of port, so policies referencing applications enforce intent precisely and resist evasion via port hopping. This satisfies production best practice by removing reliance on port numbers, which are unreliable indicators of actual application traffic.

Why this answer

Option C is correct because App-ID's core value is identifying applications regardless of port, protocol, or evasive technique, so security policies should reference applications (or application filters/groups) rather than ports to enforce accurate, consistent control. Option D is correct because App-ID alone only identifies and allows/denies traffic; pairing it with security profiles such as Vulnerability Protection, Antivirus, Anti-Spyware, and URL Filtering provides the threat inspection needed to actually block exploits and malware within allowed applications. Option A is wrong because disabling App-ID for unmatched traffic (e.g., via unknown-tcp/unknown-udp handling) weakens visibility and control rather than being a best practice, and performance is not improved in a way that justifies losing security.

Option B is wrong because port-only policies defeat the purpose of App-ID and are easily bypassed by applications using non-standard ports or port hopping. Option E is wrong because restricting to only well-known applications is not a general best practice; App-ID should be used to identify and control all applications, including sanctioned SaaS and custom/internal apps, based on risk and business need.

Exam trap

The trap here is that candidates often think disabling App-ID for unknown traffic improves performance (Option A), but this actually creates a security gap; the correct approach is to use 'default' rules with security profiles to handle unknown traffic safely.

29
MCQeasy

A network administrator wants to allow only specific applications such as 'facebook-base' and 'youtube' while blocking all other applications. Which type of security rule should be used to achieve this?

A.Create a security rule with application conditions set to 'facebook-base' and 'youtube' and action set to 'allow'.
B.Create a security rule with destination port 80 and 443 and action set to 'allow'.
C.Create a security profile that blocks all applications not in the allow list.
D.Create a URL filtering rule to allow 'social-networking' and 'multimedia' categories.
AnswerA

Application-based security rules match traffic by App-ID rather than port or IP, so specifying facebook-base and youtube with an allow action permits only those applications. An implicit deny then blocks all remaining applications, satisfying the allowlist requirement.

Why this answer

App-ID allows you to create a security rule that explicitly allows only the specified applications ('facebook-base' and 'youtube') while implicitly denying all other traffic. Since the default action for any traffic not matching an allow rule is 'deny', this rule achieves the goal of blocking all other applications without needing an explicit block rule.

Exam trap

The trap here is that candidates often confuse port-based rules (Option B) with application-based rules, assuming that allowing ports 80/443 is sufficient to control application access, but App-ID is required to distinguish between applications using the same port.

How to eliminate wrong answers

Option B is wrong because allowing destination ports 80 and 443 would permit all HTTP/HTTPS traffic, including applications like 'facebook-base' and 'youtube', but it would also allow many other web-based applications (e.g., 'twitter', 'dropbox'), failing to block them. Option C is wrong because security profiles (e.g., Antivirus, Vulnerability Protection) do not control which applications are allowed or blocked; they inspect traffic that is already permitted by the security rule's action. Option D is wrong because URL filtering rules control access based on URL categories, not application identities; 'social-networking' and 'multimedia' categories would include many applications beyond just 'facebook-base' and 'youtube', and URL filtering cannot enforce application-level granularity like App-ID can.

30
MCQhard

During a security audit, it is discovered that a custom application signature matches too broadly, causing benign traffic to be classified as the custom app. What change should be made to narrow the signature?

A.Remove the protocol field from the signature.
B.Use a wider port range and remove data patterns.
C.Add a data pattern filter to match a specific payload signature.
D.Expand the port range to include more traffic.
AnswerC

A data pattern filter constrains the signature to a distinctive payload string, so matching requires the specific byte sequence rather than broad context alone. This narrows detection to the intended application, preventing benign sessions that merely resemble the app from being classified as the custom app.

Why this answer

Adding a data pattern filter allows the custom App-ID signature to match on a specific payload string or byte sequence, which narrows the scope of traffic classified as that application. Without a data pattern, the signature may rely solely on IP protocol, port, or other broad criteria, causing false positives. By requiring a unique payload signature, only traffic containing that exact data pattern is identified as the custom application.

Exam trap

The trap here is that candidates mistakenly think expanding port ranges or removing protocol fields will narrow the signature, when in fact those actions broaden the match criteria and worsen false positives.

How to eliminate wrong answers

Option A is wrong because removing the protocol field would make the signature even broader, potentially matching any IP traffic regardless of protocol (TCP, UDP, etc.), increasing false positives. Option B is wrong because using a wider port range and removing data patterns would expand the matching criteria, making the signature less specific and more likely to misclassify benign traffic. Option D is wrong because expanding the port range includes more traffic, which would broaden the signature and worsen the over-matching issue, not narrow it.

31
Multi-Selecthard

Which THREE of the following can cause App-ID to incorrectly identify traffic?

Select 3 answers
A.Multiple security rules are configured for the same traffic.
B.Asymmetric routing causes the firewall to see only one direction of traffic.
C.SSL decryption is not enabled for the traffic.
D.IP fragmentation occurs before the firewall.
E.Traffic is forwarded through an HTTP proxy.
AnswersB, C, D

Asymmetric routing can prevent the firewall from seeing the full session, causing inaccurate identification.

Why this answer

Asymmetric routing causes App-ID to see only one direction of traffic (e.g., SYN but no SYN-ACK). App-ID relies on bidirectional flow inspection to identify applications; without seeing both directions, the firewall cannot complete the application signature match or protocol handshake, leading to incorrect or failed identification.

Exam trap

The trap here is that candidates often think IP fragmentation is a rare or non-impactful scenario, but it directly prevents App-ID from seeing complete application headers, making it a common cause of misidentification in real-world networks.

32
MCQmedium

An organization uses a SaaS application that runs on a dynamic set of IP addresses. The application traffic is currently identified as ssl and not as the specific application. How can the administrator improve application identification for this SaaS application?

A.Disable App-ID for that traffic to reduce overhead.
B.Create a custom application with hostname conditions.
C.Use a port-based application override.
D.Configure a URL filtering category for the application.
AnswerB

Hostname conditions inspect the TLS SNI or HTTP Host header, which stays constant even as the SaaS provider rotates IP addresses. This lets App-ID identify the application by name rather than relying on static IPs, resolving the dynamic-address constraint that currently forces classification as generic ssl.

Why this answer

App-ID can identify SaaS applications by hostname conditions when the application uses a dynamic set of IP addresses. By creating a custom application with hostname conditions (e.g., matching the FQDN of the SaaS service), the firewall can accurately identify the traffic as that specific application rather than generic SSL, even as the backend IPs change. This leverages the firewall's ability to inspect the Server Name Indication (SNI) field in the TLS handshake or the HTTP Host header.

Exam trap

The trap here is that candidates often assume port-based overrides (Option C) are the only way to identify traffic, but they fail to recognize that hostname-based conditions in custom applications provide a more precise and dynamic identification method for SaaS applications with changing IP addresses.

How to eliminate wrong answers

Option A is wrong because disabling App-ID would prevent all application identification, making the traffic even less identifiable and defeating the purpose of improving application identification. Option C is wrong because a port-based application override maps traffic to an application based solely on the destination port (e.g., TCP 443), which would not distinguish this SaaS application from any other HTTPS traffic and would not leverage hostname or SNI. Option D is wrong because URL filtering categories are based on URL patterns and categories, not on application identity; configuring a URL filtering category would not change how App-ID classifies the traffic, and the traffic would still be identified as ssl rather than the specific application.

33
MCQmedium

An engineer checks the application counter and sees that my-custom-app has zero packets, but they expected traffic from 10.0.0.0/24 to 10.1.0.0/24 to be identified as my-custom-app. What is the most likely reason?

A.The traffic is being identified as ssl instead.
B.The application override rule does not have the correct port.
C.The security policy does not allow the traffic.
D.The custom application my-custom-app is not committed.
AnswerB

Application override rules match on the port defined in the override, not the signature's default. If the configured port differs from the actual destination port carrying the traffic, the override never triggers, so the custom app counter stays at zero despite matching source and destination subnets.

Why this answer

An application override rule explicitly maps traffic to a custom application based on IP address, protocol, and port. If the port in the override rule does not match the actual destination port used by the traffic (e.g., TCP/8080 instead of TCP/80), the firewall will not classify the traffic as my-custom-app, resulting in zero packets for that application counter. The traffic may still pass but will be identified by App-ID as another application or remain unidentified.

Exam trap

The trap here is that candidates often assume the issue is with the security policy blocking traffic (Option C) or with the application not being committed (Option D), but the zero-packet counter specifically for the custom app points to a matching failure in the override rule, not a policy or commit problem.

How to eliminate wrong answers

Option A is wrong because if the traffic were identified as ssl, the application counter for my-custom-app would still show zero packets, but the question states the engineer expected the traffic to be identified as my-custom-app, implying an override or custom signature is in place; SSL identification would only occur if no override matched and App-ID detected SSL handshake, which is not the most likely reason given the expectation of a custom app. Option C is wrong because if the security policy did not allow the traffic, the packets would be dropped and the application counter for my-custom-app would still show zero, but the engineer would likely see deny logs or zero byte counts across all counters, not just the custom app; the question focuses on identification, not permission. Option D is wrong because if my-custom-app were not committed, the application object would not exist in the running configuration, and the firewall would not have a counter for it at all; the fact that the counter exists and shows zero packets indicates the object is committed but not matching traffic.

34
MCQeasy

A company uses a Palo Alto Networks firewall with App-ID enabled. They have a custom application that communicates over TCP port 5001. The administrator has created a custom App-ID signature and a security rule that allows this application from the internal zone (trust) to the external zone (untrust). Users report that the custom application traffic is being blocked. The administrator checks the traffic logs and sees that the sessions are being matched to a different security rule that denies any traffic from trust to untrust. The deny rule appears before the custom allow rule in the policy list. The custom App-ID signature is properly defined and tested. What should the administrator do to resolve this issue?

A.Modify the custom App-ID signature to match more precisely.
B.Create an application override for the custom application.
C.Add a virtual wire interface to ensure traffic reaches the firewall.
D.Reorder the security rules so the custom allow rule is above the deny rule.
AnswerD

Security rules are evaluated top-down, so the earlier deny rule matches the traffic before the custom allow rule is reached. Moving the allow rule above the deny rule satisfies the requirement that App-ID-permitted traffic be evaluated first, resolving the block.

Why this answer

Security rules in Palo Alto Networks firewalls are evaluated in top-down order, and the first matching rule is applied. Since the deny rule appears before the custom allow rule, all traffic matching the deny rule's criteria (including the custom application) is blocked before reaching the allow rule. Reordering the rules so the custom allow rule is above the deny rule ensures the custom application traffic is permitted as intended.

Exam trap

The trap here is that candidates often focus on App-ID configuration (options A or B) rather than recognizing that the fundamental issue is rule ordering, which is a core concept in Palo Alto Networks policy evaluation.

How to eliminate wrong answers

Option A is wrong because the custom App-ID signature is already properly defined and tested, so modifying it further would not change the rule-matching order; the issue is policy ordering, not signature accuracy. Option B is wrong because an application override bypasses App-ID identification by forcing the firewall to treat traffic as a specific application, but this does not resolve the rule-order problem; the traffic would still hit the deny rule first. Option C is wrong because a virtual wire interface is a deployment mode for transparent inline inspection and does not affect security rule evaluation order or traffic matching; the firewall is already receiving the traffic.

Ready to test yourself?

Try a timed practice session using only Securing Traffic and App-ID questions.