nerdexam
Palo_Alto_Networks

PSE-STRATA · Question #181

A prospective customer currently uses a firewall that provides only Layer 4 inspection and protections. The customer sees traffic going to an external destination, port 53, but cannot determine what…

The correct answer is D. App-ID, because it will give visibility into what exact applications are being run over that port and. App-ID is the correct answer because it is Palo Alto Networks' application identification engine that classifies traffic at Layer 7 - meaning it can inspect what application is actually running over any port, including non-standard uses of port 53 (normally DNS). A traditional…

Question

A prospective customer currently uses a firewall that provides only Layer 4 inspection and protections. The customer sees traffic going to an external destination, port 53, but cannot determine what Layer 7 application traffic is going over that port Which capability of PAN-OS would address the customer's lack of visibility?

Options

  • ADevice ID, because it will give visibility into which devices are communicating with external
  • Bsingle pass architecture (SPA), because it will improve the performance of the Palo Alto Networks
  • CUser-ID, because it will allow the customer to see which users are sending traffic to external
  • DApp-ID, because it will give visibility into what exact applications are being run over that port and

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    12% (3)
  • D
    76% (19)

Explanation

App-ID is the correct answer because it is Palo Alto Networks' application identification engine that classifies traffic at Layer 7 - meaning it can inspect what application is actually running over any port, including non-standard uses of port 53 (normally DNS). A traditional Layer 4 firewall only sees IP addresses and ports, so it can't distinguish DNS from, say, a tunneling application hiding inside port 53 traffic.

Why the distractors are wrong:

  • A (Device ID) identifies which device is communicating, but provides no insight into what application or protocol is in use.
  • B (SPA) is a performance/efficiency architecture that processes traffic in a single pass - it's about speed, not application visibility.
  • C (User-ID) maps traffic to who (the user/identity) is sending it, but doesn't reveal what Layer 7 application is generating that traffic.

Memory tip: App-ID = "What app is this?" - think of it as the inspector who looks inside the packet, not just at the address label. Any time an exam question involves unknown or suspicious applications hiding on well-known ports, App-ID is the answer.

Community Discussion

No community discussion yet for this question.

Full PSE-STRATA Practice