PCNSE · Question #865
How can a firewall engineer bypass App-ID and content inspection features on a Palo Alto Networks firewall when troubleshooting?
The correct answer is B. Create a custom application, define its properties, then create an application override and. An application override (Option B) bypasses App-ID and content inspection by forcing the firewall to classify traffic as the custom app, skipping deeper analysis. The custom app's properties (e.g., ports) define the match, and no security profiles are applied.
Question
How can a firewall engineer bypass App-ID and content inspection features on a Palo Alto Networks firewall when troubleshooting?
Options
- ACreate a custom application, define its properties and signatures, and ensure all scanning options
- BCreate a custom application, define its properties, then create an application override and
- CCreate a new security rule specifically for the affected traffic, but do not reference any Security
- DCreate a new security rule specifically for the affected traffic, and select "Disable Server
How the community answered
(25 responses)- A8% (2)
- B88% (22)
- D4% (1)
Explanation
An application override (Option B) bypasses App-ID and content inspection by forcing the firewall to classify traffic as the custom app, skipping deeper analysis. The custom app's properties (e.g., ports) define the match, and no security profiles are applied.
Topics
Community Discussion
No community discussion yet for this question.