PCNSE Securing Traffic and App-ID Practice Question
Dynamics Inc., a mid-sized company, uses Palo Alto Networks PA-5250 firewalls at their data center. They recently deployed a new web-based CRM application that uses HTTPS and WebSocket connections on TCP port 8443. The security team configured a custom application 'crm-app' with a signature that matches the 'Host' header in HTTP requests, and set the protocol decoder to 'tcp' and the port to 8443. The application is used in a security policy to allow traffic from internal users to the CRM server. However, after deployment, the traffic logs show the application is identified as 'ssl' instead of 'crm-app'. The firewall's App-ID and threat prevention subscriptions are active and up to date. The team has verified that the custom application signature is correctly configured, and the traffic clearly matches the defined host header. Which action should be taken to ensure the CRM traffic is correctly identified by App-ID?
⚠ Common exam trap
Watch out — candidates often assume a correctly configured custom application signature will always identify traffic, but they overlook that encrypted payloads (HTTPS/WebSocket) prevent the firewall from inspecting HTTP headers, making the signature ineffective without SSL decryption or an application override.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new security rule with an application override that sets the application to 'crm-app' for the CRM traffic.
When a custom application signature fails to identify traffic due to the firewall's inability to inspect encrypted payloads (like HTTPS/WebSocket), an application override in a security rule forces App-ID to classify the traffic as the specified application regardless of the signature match. Since the CRM traffic uses HTTPS on port 8443, the firewall sees encrypted SSL/TLS handshakes and defaults to 'ssl' App-ID because it cannot inspect the encrypted HTTP headers. An application override bypasses the App-ID identification process and directly assigns the desired application, ensuring correct logging and policy enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the 'timeout' value for the custom application signature from 0 to 60 seconds.
Why it's wrong here
The timeout value determines how long App-ID waits before it updates the application identification; it does not affect the initial identification process.
- ✗
Modify the custom application signature to use the 'tcp' protocol decoder and set the port to 8443.
Why it's wrong here
The protocol decoder and port are already correctly configured as verified; this change is unnecessary and would not resolve the misclassification.
- ✗
Disable SSL decryption for the CRM traffic to allow App-ID to inspect the unencrypted HTTP headers.
Why it's wrong here
Disabling SSL decryption would not help; it would prevent App-ID from inspecting HTTP headers in encrypted traffic, potentially making identification worse.
- ✓
Create a new security rule with an application override that sets the application to 'crm-app' for the CRM traffic.
Why this is correct
An application override forces the firewall to identify the traffic as the specified application, bypassing App-ID's detection. This is a valid approach when App-ID fails to correctly classify traffic despite a properly configured custom signature.
Visual reference
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 504-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.