nerdexam
Palo_Alto_Networks

PCNSE · Question #165

Which event will happen if an administrator uses an Application Override Policy?

The correct answer is B. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.. An Application Override Policy instructs the Palo Alto Networks NGFW to stop App-ID processing at Layer 4 (TCP/UDP) once a match is found. Normally, App-ID performs deep packet inspection up through Layer 7 to identify the application. When an override is applied, the firewall sk

Submitted by andres_qro· Apr 18, 2026Deploy and Configure

Question

Which event will happen if an administrator uses an Application Override Policy?

Options

  • AThreat-ID processing time is decreased.
  • BThe Palo Alto Networks NGFW stops App-ID processing at Layer 4.
  • CThe application name assigned to the traffic by the security rule is written to the Traffic log.
  • DApp-ID processing time is increased.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    95% (38)
  • D
    3% (1)

Explanation

An Application Override Policy instructs the Palo Alto Networks NGFW to stop App-ID processing at Layer 4 (TCP/UDP) once a match is found. Normally, App-ID performs deep packet inspection up through Layer 7 to identify the application. When an override is applied, the firewall skips this Layer 7 inspection and assigns the application name manually defined in the policy. This reduces security visibility (no Threat Prevention, no App-ID signatures) but can be useful for custom or proprietary applications. It does NOT increase App-ID processing time (D), and the application name written to the Traffic log is the one defined in the override rule-not one discovered by App-ID (making C incorrect as phrased). Threat-ID processing (A) is also bypassed entirely, not just decreased.

Topics

#Application Override#App-ID#Policy Enforcement#Traffic Processing

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice