PCNSE Securing Traffic and App-ID Practice Question
Which THREE of the following can cause App-ID to incorrectly identify traffic?
⚠ Common exam trap
Watch out — candidates often think IP fragmentation is a rare or non-impactful scenario, but it directly prevents App-ID from seeing complete application headers, making it a common cause of misidentification in real-world networks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Asymmetric routing causes the firewall to see only one direction of traffic.
Asymmetric routing causes App-ID to see only one direction of traffic (e.g., SYN but no SYN-ACK). App-ID relies on bidirectional flow inspection to identify applications; without seeing both directions, the firewall cannot complete the application signature match or protocol handshake, leading to incorrect or failed identification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multiple security rules are configured for the same traffic.
Why it's wrong here
Multiple rules do not affect App-ID identification.
- ✓
Asymmetric routing causes the firewall to see only one direction of traffic.
Why this is correct
Asymmetric routing can prevent the firewall from seeing the full session, causing inaccurate identification.
- ✓
SSL decryption is not enabled for the traffic.
Why this is correct
Without decryption, App-ID cannot inspect encrypted payloads, leading to potential incorrect identification.
- ✓
IP fragmentation occurs before the firewall.
Why this is correct
Fragmentation can obscure application signatures, leading to misidentification.
- ✗
Traffic is forwarded through an HTTP proxy.
Why it's wrong here
HTTP proxies can be handled by App-ID.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.