nerdexam
Palo_Alto_Networks

PCNSE · Question #10

Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application is very sensitive…

The correct answer is D. Create a Custom Application with signatures matching unique identifiers of the in-house. Since the in-house application is sensitive and must be inspected by the Content-ID engine, the correct approach is to create a Custom Application with signatures that match unique identifiers (headers, patterns, payloads) of the in-house application (D). This allows the…

Submitted by kev92· Apr 18, 2026Deploy and Configure

Question

Company.com has an in-house application that the Palo Alto Networks device doesn't identify correctly. A Threat Management Team member has mentioned that this in-house application is very sensitive and all traffic being identified needs to be inspected by the Content-ID engine. Which method should company.com use to immediately address this traffic on a Palo Alto Networks device?

Options

  • ACreate a custom Application without signatures, then create an Application Override policy that
  • BWait until an official Application signature is provided from Palo Alto Networks.
  • CModify the session timer settings on the closest referanced application to meet the needs of the
  • DCreate a Custom Application with signatures matching unique identifiers of the in-house

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    3% (1)
  • C
    6% (2)
  • D
    82% (27)

Explanation

Since the in-house application is sensitive and must be inspected by the Content-ID engine, the correct approach is to create a Custom Application with signatures that match unique identifiers (headers, patterns, payloads) of the in-house application (D). This allows the firewall to correctly identify the application using App-ID while still passing traffic through the Content-ID engine for threat inspection, URL filtering, and file blocking. Application Override (A) is explicitly the wrong choice here - Application Override bypasses both the App-ID and Content-ID engines, which directly contradicts the requirement for Content-ID inspection. Waiting for an official signature (B) is not immediate. Modifying session timers (C) does not address identification or inspection.

Topics

#Custom Applications#App-ID#Content-ID#Traffic Identification

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice