nerdexam
Palo_Alto_Networks

PCNSE · Question #734

Why would a traffic log list an application as "not-applicable"?

The correct answer is C. The firewall denied the traffic before the application match could be performed. If traffic hits a security rule that's set to "deny," based on any parameter before the application, the traffic log shows the application as not-applicable. This occurs because the traffic was dropped or denied before the application match could be performed.

Submitted by yasin.bd· Apr 18, 2026Core Concepts

Question

Why would a traffic log list an application as "not-applicable"?

Options

  • AThere was not enough application data after the TCP connection was established.
  • BThe TCP connection terminated without identifying any application data.
  • CThe firewall denied the traffic before the application match could be performed.
  • DThe application is not a known Palo Alto Networks App-ID.

How the community answered

(46 responses)
  • A
    4% (2)
  • C
    93% (43)
  • D
    2% (1)

Explanation

If traffic hits a security rule that's set to "deny," based on any parameter before the application, the traffic log shows the application as not-applicable. This occurs because the traffic was dropped or denied before the application match could be performed.

Topics

#Traffic Logs#App-ID#Policy Enforcement#Log Interpretation

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice