nerdexam
Palo_Alto_Networks

PCNSE · Question #865

How can a firewall engineer bypass App-ID and content inspection features on a Palo Alto Networks firewall when troubleshooting?

The correct answer is B. Create a custom application, define its properties, then create an application override and. An application override (Option B) bypasses App-ID and content inspection by forcing the firewall to classify traffic as the custom app, skipping deeper analysis. The custom app's properties (e.g., ports) define the match, and no security profiles are applied.

Submitted by deeparc· Apr 18, 2026Configuration Troubleshooting

Question

How can a firewall engineer bypass App-ID and content inspection features on a Palo Alto Networks firewall when troubleshooting?

Options

  • ACreate a custom application, define its properties and signatures, and ensure all scanning options
  • BCreate a custom application, define its properties, then create an application override and
  • CCreate a new security rule specifically for the affected traffic, but do not reference any Security
  • DCreate a new security rule specifically for the affected traffic, and select "Disable Server

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    88% (22)
  • D
    4% (1)

Explanation

An application override (Option B) bypasses App-ID and content inspection by forcing the firewall to classify traffic as the custom app, skipping deeper analysis. The custom app's properties (e.g., ports) define the match, and no security profiles are applied.

Topics

#Application override#App-ID bypass#Content inspection bypass#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice