nerdexam
Palo_Alto_Networks

PCNSE · Question #181

An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's proprieta

Sign in or unlock PCNSE to reveal the answer and full explanation for question #181. The question stem and answer options stay visible for context.

Submitted by asante_acc· Apr 18, 2026Deploy and Configure

Question

An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's proprietary accounting application. The administrator wants to reliably identify this traffic as their accounting application and to scan this traffic for threats. Which option would achieve this result?

Options

  • ACreate a custom App-ID and enable scanning on the advanced tab.
  • BCreate an Application Override policy.
  • CCreate a custom App-ID and use the "ordered conditions" check box.
  • DCreate an Application Override policy and custom threat signature for the application.

Unlock PCNSE to see the answer

You've previewed enough free PCNSE questions. Unlock PCNSE for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#App-ID#Custom Applications#Threat Prevention#Security Policy
Full PCNSE Practice