PCNSE · Question #165
Which event will happen if an administrator uses an Application Override Policy?
The correct answer is B. The Palo Alto Networks NGFW stops App-ID processing at Layer 4.. An Application Override Policy instructs the Palo Alto Networks NGFW to stop App-ID processing at Layer 4 (TCP/UDP) once a match is found. Normally, App-ID performs deep packet inspection up through Layer 7 to identify the application. When an override is applied, the firewall sk
Question
Which event will happen if an administrator uses an Application Override Policy?
Options
- AThreat-ID processing time is decreased.
- BThe Palo Alto Networks NGFW stops App-ID processing at Layer 4.
- CThe application name assigned to the traffic by the security rule is written to the Traffic log.
- DApp-ID processing time is increased.
How the community answered
(40 responses)- A3% (1)
- B95% (38)
- D3% (1)
Explanation
An Application Override Policy instructs the Palo Alto Networks NGFW to stop App-ID processing at Layer 4 (TCP/UDP) once a match is found. Normally, App-ID performs deep packet inspection up through Layer 7 to identify the application. When an override is applied, the firewall skips this Layer 7 inspection and assigns the application name manually defined in the policy. This reduces security visibility (no Threat Prevention, no App-ID signatures) but can be useful for custom or proprietary applications. It does NOT increase App-ID processing time (D), and the application name written to the Traffic log is the one defined in the override rule-not one discovered by App-ID (making C incorrect as phrased). Threat-ID processing (A) is also bypassed entirely, not just decreased.
Topics
Community Discussion
No community discussion yet for this question.