Courseiva

PCNSE · topic practice

Securing Traffic and App-ID practice questions

This domain covers App-ID classification and policy enforcement on Palo Alto Networks firewalls. Questions test why App-ID misidentifies traffic, how to block applications like BitTorrent while allowing SFTP on the same port, and how to handle unknown-tcp or custom UDP protocols using application overrides and custom App-IDs.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Securing Traffic and App-ID

What the exam tests

What to know about Securing Traffic and App-ID

You must be able to explain App-ID misidentification causes, create custom App-IDs for proprietary protocols, and use application-based policies to block BitTorrent while allowing SFTP on the same port. The most important thing is that App-ID identifies applications by signature, not port.

App-ID identification of applications using ports, signatures, and protocol decoders

Creating custom App-IDs for proprietary TCP or UDP protocols

Using application filters and groups to block file-sharing like BitTorrent

Troubleshooting unknown-tcp and unknown-udp in traffic logs

Watch out for

Common Securing Traffic and App-ID exam traps

  • ▸Assuming port-based rules can block BitTorrent while allowing SFTP on port 22; App-ID decodes the application regardless of port.
  • ▸Forgetting that custom App-IDs require signature and context configuration; incomplete definitions cause unknown-tcp.
  • ▸Believing App-ID will identify proprietary protocols without custom signatures; unknown-tcp appears until a custom App-ID is created.

Practice set

Securing Traffic and App-ID questions

20 questions · select your answer, then reveal the explanation

A security engineer notices that traffic from a trusted internal application is being blocked by the firewall. The application communicates using a proprietary protocol over TCP port 8443. The engineer has already created a custom App-ID for this application but the traffic is still being blocked. What is the most likely reason?

An administrator notices that traffic for a known application 'ms-update' is being blocked. The security policy has a rule allowing 'ms-update' from the internal network to the internet. However, the traffic is being denied. What should the administrator check first?

Which TWO of the following are valid methods to create a custom App-ID on a Palo Alto Networks firewall?

Refer to the exhibit. A network engineer wants to allow only 'ms-update' and 'facebook-base' traffic. After committing the above security policy, they find that 'ssl' traffic is also being allowed. What is the most likely reason?

Exhibit

Refer to the exhibit.

admin@PA-220> show running security-policy | match app
rule id 1: application any -> allow
rule id 2: application ms-update, facebook-base -> allow
rule id 3: application ssl, web-browsing -> allow
rule id 4: application any -> deny

A security engineer is troubleshooting a Palo Alto Networks firewall where HTTP traffic is being incorrectly identified by App-ID. The engineer has verified that the application is correctly configured in the application override policy. Which two factors could cause App-ID to fail to recognize the application?

Refer to the exhibit. A network engineer notices high CPU utilization on the firewall. The output shows that 4500 sessions are pending App-ID identification. What is the most likely cause of the high number of pending sessions?

Exhibit

Refer to the exhibit.

show system state | match appid
total appid sessions: 12000
appid pending sessions: 4500
appid complete sessions: 7500
appid error sessions: 0

A network engineer is troubleshooting an issue where a web application is being incorrectly identified as 'web-browsing' instead of 'webmail-gmail' by the Palo Alto Networks firewall. The firewall has App-ID enabled and all signatures are up to date. Which TWO actions should the engineer take to resolve this misidentification?

Match each PAN-OS component to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Handles configuration, logging, and reporting

Processes traffic and enforces security policies

Manages routing and session setup

Collects and stores logs for analysis

Centralized management for multiple firewalls

Match each decryption type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Decrypts outbound traffic to inspect it

Decrypts inbound traffic to servers

Decrypts SSH traffic for policy enforcement

Traffic bypasses decryption

Sends decrypted traffic to a monitoring tool

An engineer wants to block all peer-to-peer file sharing traffic using App-ID. What security policy action should be used?

A security team is deploying SSL Decryption for inbound traffic to protect against threats hidden in encrypted traffic. However, they want to exclude financial transactions that use client certificates for authentication. What is the best approach?

A company has a Palo Alto Networks firewall in a high-availability active/passive setup. After a failover event, the new active firewall is not correctly identifying some custom applications. The custom application objects and signatures are synchronized via Panorama. What is the most likely cause?

An administrator is configuring SSL Forward Proxy decryption and wants to ensure that traffic to internal servers with self-signed certificates is decrypted, but traffic to external banking sites is excluded from decryption. They have created a decryption policy with two rules: first rule with 'No Decrypt' for the external banking URLs, second rule with 'Decrypt' for all other traffic. However, the banking traffic is still being decrypted. What is the most likely issue?

A network security engineer is troubleshooting an issue where certain VoIP traffic is being dropped by the firewall. The traffic logs show that the application is identified as 'voip' and the security rule allows 'voip'. However, the traffic is still being dropped. What should the engineer check next?

A security administrator needs to block an application that uses multiple ports, including dynamic ports. Which of the following methods can be used to block this application using App-ID? (Choose two.)

During a security incident, an analyst notices that certain malware traffic is using port 443 but is being identified as 'ssl'. The malware uses a unique handshake that differs from standard SSL. Which two actions should the analyst take to correctly identify and block this malware? (Choose two.)

Given the security policy above, what will happen to an HTTP request from a user to a public website?

Exhibit

Refer to the exhibit.
show running security-policy
rule 1 name "Allow-Web"
  source any
  destination any
  application web-browsing
  action allow
  profile threat
rule 2 name "Block-All"
  source any
  destination any
  application any
  action deny

A threat log entry shows a threat detected in SSL traffic to 10.0.0.5, which is a server in the internal network. However, the decryption policy has a rule to no-decrypt traffic to 10.0.0.0/8 from internal sources. What is the most likely reason the threat was detected?

Exhibit

Refer to the exhibit.
admin@PA-1> show system info | match model
model: PA-5250
admin@PA-1> show running decryption policy
rule 1 name "No-Decrypt-Internal"
  source 192.168.0.0/16
  destination 10.0.0.0/8
  service https
  action no-decrypt
rule 2 name "Decrypt-All"
  source any
  destination any
  service https
  action decrypt
  profile "default-forward-proxy"
admin@PA-1> show running security policy
rule 1 name "Allow-All"
  source any
  destination any
  application any
  service https
  action allow
  profile threat
admin@PA-1> show threat log | match 10.0.0.5
<log entry: threat detected in SSL traffic>

A network administrator notices that web-browsing traffic is being classified as 'incomplete' in the App-ID table. What is the most likely cause?

A company uses a custom application for internal VoIP traffic. The custom App-ID signature is configured with the correct protocol and port, but traffic is still not matching. The firewall shows the application as 'unknown-tcp'. What should the administrator check next?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Securing Traffic and App-ID sessions

Start a Securing Traffic and App-ID only practice session

Every question in these sessions is drawn from the Securing Traffic and App-ID domain — nothing else.

Related practice questions

Related PCNSE topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PCNSE exam test about Securing Traffic and App-ID?
You must be able to explain App-ID misidentification causes, create custom App-IDs for proprietary protocols, and use application-based policies to block BitTorrent while allowing SFTP on the same port. The most important thing is that App-ID identifies applications by signature, not port.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Securing Traffic and App-ID questions in a focused session?
Yes — the session launcher on this page draws every question from the Securing Traffic and App-ID domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PCNSE topics?
Use the topic links above to move to related areas, or go back to the PCNSE question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PCNSE exam covers. They are not copied from any real exam or dump site.