nerdexam
Palo_Alto_Networks

PCNSE · Question #719

With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?

The correct answer is C. not-applicable. The answer 'not-applicable' (C) is assigned when App-ID does not apply to the traffic type in question - most commonly for non-TCP/UDP protocols such as ICMP, GRE, or other Layer 4 protocols that carry no application payload for App-ID to inspect. Given the default TCP/UDP…

Submitted by lucia.co· Apr 18, 2026Operate

Question

With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?

Exhibit

PCNSE question #719 exhibit

Options

  • Ainsufficient-data
  • Bincomplete
  • Cnot-applicable
  • Dunknown-tcp

How the community answered

(23 responses)
  • C
    96% (22)
  • D
    4% (1)

Explanation

The answer 'not-applicable' (C) is assigned when App-ID does not apply to the traffic type in question - most commonly for non-TCP/UDP protocols such as ICMP, GRE, or other Layer 4 protocols that carry no application payload for App-ID to inspect. Given the default TCP/UDP settings on the firewall and the session shown in the (referenced) graphic, the traffic is a non-TCP/UDP protocol session, so App-ID classification is not applicable. 'incomplete' (B) applies to TCP sessions where the three-way handshake never finished. 'insufficient-data' (A) applies when a TCP/UDP session completed setup but did not carry enough payload bytes for App-ID to make a determination. 'unknown-tcp' (D) applies when a TCP session carried data but App-ID could not match it to a known application signature.

Topics

#App-ID#Session Identification#Firewall Basics#App-ID States

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice