nerdexam
Palo_Alto_Networks

PCNSA · Question #379

An administrator reads through the following Applications and Threats Content Release Notes before an update: Which rule would continue to allow the file upload to confluence after the update? A. B…

The correct answer is A. Rule with Application: 'confluence uploading', Service: 'web-browsing'. When a PAN-OS content update introduces a new, more specific App-ID (such as splitting 'confluence uploading' from a broader parent application), rules using the parent application with 'application-default' service may stop matching upload traffic because the child application…

Submitted by tunde_lagos· Apr 18, 2026Policy Evaluation and Management

Question

An administrator reads through the following Applications and Threats Content Release Notes before an update:

Which rule would continue to allow the file upload to confluence after the update? A. B. C. D.

Exhibits

PCNSA question #379 exhibit 1
PCNSA question #379 exhibit 2
PCNSA question #379 exhibit 3
PCNSA question #379 exhibit 4

Options

  • ARule with Application: 'confluence uploading', Service: 'web-browsing'
  • BRule with Application: 'confluence base', Service: 'web-browsing'
  • CRule with Application: 'confluence uploading', Service: 'application-default'
  • DRule with Application: 'confluence base', Service: 'application-default'

How the community answered

(62 responses)
  • A
    65% (40)
  • B
    5% (3)
  • C
    23% (14)
  • D
    8% (5)

Explanation

When a PAN-OS content update introduces a new, more specific App-ID (such as splitting 'confluence uploading' from a broader parent application), rules using the parent application with 'application-default' service may stop matching upload traffic because the child application may use different port defaults than the parent. A rule explicitly specifying 'confluence uploading' as the application with 'web-browsing' as the service will continue to allow file uploads - it matches the specific sub-application and permits traffic on any standard web port, making it resilient to content update-driven App-ID splits.

Topics

#Security Policy#App-ID#Content Updates#Policy Evaluation

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice