PCNSE · Question #10
Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application is very sensitive…
The correct answer is D. Create a Custom Application with signatures matching unique identifiers of the in-house. Since the in-house application is sensitive and must be inspected by the Content-ID engine, the correct approach is to create a Custom Application with signatures that match unique identifiers (headers, patterns, payloads) of the in-house application (D). This allows the…
Question
Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application is very sensitive and all traffic being identified needs to be inspected by the Content-ID engine. Which method should company.com use to immediately address this traffic on a Palo Alto Networks device?
Options
- ACreate a custom Application without signatures, then create an Application Override policy that
- BWait until an official Application signature is provided from Palo Alto Networks.
- CModify the session timer settings on the closest referanced application to meet the needs of the
- DCreate a Custom Application with signatures matching unique identifiers of the in-house
How the community answered
(33 responses)- A9% (3)
- B3% (1)
- C6% (2)
- D82% (27)
Explanation
Since the in-house application is sensitive and must be inspected by the Content-ID engine, the correct approach is to create a Custom Application with signatures that match unique identifiers (headers, patterns, payloads) of the in-house application (D). This allows the firewall to correctly identify the application using App-ID while still passing traffic through the Content-ID engine for threat inspection, URL filtering, and file blocking. Application Override (A) is explicitly the wrong choice here - Application Override bypasses both the App-ID and Content-ID engines, which directly contradicts the requirement for Content-ID inspection. Waiting for an official signature (B) is not immediate. Modifying session timers (C) does not address identification or inspection.
Topics
Community Discussion
No community discussion yet for this question.