nerdexam
Palo_Alto_Networks

PCNSE · Question #639

An administrator is receiving complaints about application performance degradation. After checking the ACC, the administrator observes that there is an excessive amount of SSL traffic. Which three…

The correct answer is C. A QoS profile defining traffic classes D. A QoS policy for each application ID E. An Application Override policy for the SSL traffic. To mitigate performance degradation from excessive SSL traffic, an administrator should define traffic classes with a QoS profile, apply QoS policies to specific application IDs, and consider an Application Override policy for known SSL applications.

Submitted by ravi_2018· Apr 18, 2026Deploy and Configure

Question

An administrator is receiving complaints about application performance degradation. After checking the ACC, the administrator observes that there is an excessive amount of SSL traffic. Which three elements should the administrator configure to address this issue? (Choose three.)

Options

  • AQoS on the egress interface for the traffic flows
  • BQoS on the ingress interface for the traffic flows
  • CA QoS profile defining traffic classes
  • DA QoS policy for each application ID
  • EAn Application Override policy for the SSL traffic

How the community answered

(54 responses)
  • A
    7% (4)
  • B
    19% (10)
  • C
    74% (40)

Why each option

To mitigate performance degradation from excessive SSL traffic, an administrator should define traffic classes with a QoS profile, apply QoS policies to specific application IDs, and consider an Application Override policy for known SSL applications.

AQoS on the egress interface for the traffic flows

While QoS is applied to interfaces, configuring it only on the egress interface for traffic flows is incomplete; it needs a comprehensive QoS framework including profiles and policies.

BQoS on the ingress interface for the traffic flows

While QoS is applied to interfaces, configuring it only on the ingress interface for traffic flows is incomplete; it needs a comprehensive QoS framework including profiles and policies.

CA QoS profile defining traffic classesCorrect

A QoS profile is essential to define different traffic classes based on performance requirements, enabling the firewall to prioritize or deprioritize specific types of traffic.

DA QoS policy for each application IDCorrect

QoS policies are then used to map specific applications, like those identified by their application ID, to the defined QoS traffic classes for proper traffic management.

EAn Application Override policy for the SSL trafficCorrect

An Application Override policy can be configured for known SSL applications to classify them as a specific application earlier in the session, which can prevent the firewall from unnecessarily decrypting and re-encrypting traffic that doesn't require deep inspection, thus reducing CPU load and improving performance.

Concept tested: QoS configuration and SSL performance optimization

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/qos/qos-overview

Topics

#QoS#Application Override#Performance Tuning#SSL Inspection

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice