PCNSE Securing Traffic and App-ID Practice Question
Which TWO settings must be configured in a security policy rule to ensure the rule only matches when a specific application is detected on its standard port?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the Service to 'application-default'.
To ensure a security policy rule matches only when a specific application is detected on its standard port, two settings are required: Set the Application to the specific application to match that application's traffic, and set the Service to 'application-default' to restrict matching to the standard port used by that application. This prevents other applications using the same port from triggering the rule. The other options are not directly related to this requirement: Source and Destination zones are necessary for any rule but not specific to application/port matching; Threat Prevention is a separate feature; logging at session start is optional and does not affect matching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the Source Zone and Destination Zone.
Why it's wrong here
Zones are required but not specific to application matching.
- ✗
Enable Threat Prevention.
Why it's wrong here
Threat Prevention is a security profile, not a matching criterion.
- ✓
Set the Service to 'application-default'.
Why this is correct
application-default restricts the rule to the application's default port.
- ✗
Configure Logging at session start.
Why it's wrong here
Logging does not affect rule matching.
- ✓
Set the Application to the specific application.
Why this is correct
The application field determines which app identity the rule matches.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.