PSE-STRATA · Question #181
A prospective customer currently uses a firewall that provides only Layer 4 inspection and protections. The customer sees traffic going to an external destination, port 53, but cannot determine what…
The correct answer is D. App-ID, because it will give visibility into what exact applications are being run over that port and. App-ID is the correct answer because it is Palo Alto Networks' application identification engine that classifies traffic at Layer 7 - meaning it can inspect what application is actually running over any port, including non-standard uses of port 53 (normally DNS). A traditional…
Question
A prospective customer currently uses a firewall that provides only Layer 4 inspection and protections. The customer sees traffic going to an external destination, port 53, but cannot determine what Layer 7 application traffic is going over that port Which capability of PAN-OS would address the customer's lack of visibility?
Options
- ADevice ID, because it will give visibility into which devices are communicating with external
- Bsingle pass architecture (SPA), because it will improve the performance of the Palo Alto Networks
- CUser-ID, because it will allow the customer to see which users are sending traffic to external
- DApp-ID, because it will give visibility into what exact applications are being run over that port and
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C12% (3)
- D76% (19)
Explanation
App-ID is the correct answer because it is Palo Alto Networks' application identification engine that classifies traffic at Layer 7 - meaning it can inspect what application is actually running over any port, including non-standard uses of port 53 (normally DNS). A traditional Layer 4 firewall only sees IP addresses and ports, so it can't distinguish DNS from, say, a tunneling application hiding inside port 53 traffic.
Why the distractors are wrong:
- A (Device ID) identifies which device is communicating, but provides no insight into what application or protocol is in use.
- B (SPA) is a performance/efficiency architecture that processes traffic in a single pass - it's about speed, not application visibility.
- C (User-ID) maps traffic to who (the user/identity) is sending it, but doesn't reveal what Layer 7 application is generating that traffic.
Memory tip: App-ID = "What app is this?" - think of it as the inspector who looks inside the packet, not just at the address label. Any time an exam question involves unknown or suspicious applications hiding on well-known ports, App-ID is the answer.
Community Discussion
No community discussion yet for this question.