nerdexam
Palo_Alto_Networks

PCNSA · Question #66

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base. On a content…

The correct answer is A. All traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer. To allow the new applications, we need to modify or add a new policy. https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/manage-new-app-ids- introduced-in-content-releases/review-new-app-id-impact-on-existing-policy-rules

Submitted by kim_seoul· Apr 18, 2026Policy Evaluation and Management

Question

A security administrator has configured App-ID updates to be automatically downloaded and installed. The company is currently using an application identified by App-ID as SuperApp_base. On a content update notice, Palo Alto Networks is adding new app signatures labeled SuperApp_chat and SuperApp_download, which will be deployed in 30 days. Based on the information, how is the SuperApp traffic affected after the 30 days have passed?

Options

  • AAll traffic matching the SuperApp_chat, and SuperApp_download is denied because it no longer
  • BNo impact because the apps were automatically downloaded and installed
  • CNo impact because the firewall automatically adds the rules to the App-ID interface
  • DAll traffic matching the SuperApp_base, SuperApp_chat, and SuperApp_download is denied until

How the community answered

(27 responses)
  • A
    78% (21)
  • B
    4% (1)
  • C
    4% (1)
  • D
    15% (4)

Explanation

To allow the new applications, we need to modify or add a new policy. https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/app-id/manage-new-app-ids- introduced-in-content-releases/review-new-app-id-impact-on-existing-policy-rules

Topics

#App-ID#Security Policy#Content Updates#Application Control

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice