exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 93 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 93
Topic #: 1
[All PCNSE Questions]

The firewall identifies a popular application as an unknown-tcp.
Which two options are available to identify the application? (Choose two.)

  • A. Create a custom application.
  • B. Create a custom object for the custom application server to identify the custom application.
  • C. Submit an App-ID request to Palo Alto Networks.
  • D. Create a Security policy to identify the custom application.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Edu147
Highly Voted 5 years, 3 months ago
Correct A, C C is not apple-id, is app-id https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/app-id/manage-custom-or-unknown-applications#
upvoted 17 times
...
ochc
Highly Voted 3 years, 11 months ago
The statement says "The firewall identifies a popular application as an unknown-tcp". It doesn't say traffic is being dropped. If it identifies it, that means a rule is already in place. It also says popular, and as per https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/manage-custom-or-unknown-applications#, "...If the packet capture reveals that the application is a commercial application, you can submit this packet capture to Palo Alto Networks for App-ID development...". Commercial equates to popular. I say AC
upvoted 9 times
...
Marshpillowz
Most Recent 9 months, 2 weeks ago
Selected Answer: AC
A and C correct.
upvoted 1 times
...
Techn
1 year, 4 months ago
A&C is correct: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clu2CAC
upvoted 2 times
...
TAKUM1y
2 years, 1 month ago
Selected Answer: AC
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/manage-custom-or-unknown-applications
upvoted 3 times
...
Kuronekosama
2 years, 2 months ago
Selected Answer: AD
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/manage-custom-or-unknown-applications Actually shows A,C,D as all viable options. Great... I think A & D actually provide solutions, versus waiting on Palo to build you something that you will need to wait for.
upvoted 1 times
Gabriel2022
2 years, 2 months ago
ITs handle not identify ... A&C Create security policies to control unknown applications by unknown TCP, unknown UDP or by a combination of source zone, destination zone, and IP addresses.
upvoted 1 times
...
...
UFanat
2 years, 4 months ago
Selected Answer: AC
You can create a custom app: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/use-application-objects-in-policy/create-a-custom-application or submit a request to PAN https://www.paloaltonetworks.com/blog/submit-an-application/
upvoted 2 times
...
Meira088
2 years, 5 months ago
Selected Answer: AC
https://docs.paloaltonetworks.com/pan-os/8-0/pan-os-admin/app-id/manage-custom-or-unknown-applications#
upvoted 1 times
...
AbuHussain
2 years, 7 months ago
Selected Answer: AC
Correct A, C
upvoted 1 times
...
WATU
2 years, 7 months ago
Correct A, C. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/manage-custom-or-unknown-applications Check that the article mentioned "Create security policies to control unknown application" No to Identify as the option D
upvoted 1 times
...
FS68
3 years ago
A C correct
upvoted 2 times
...
anak1n
3 years, 6 months ago
Go on the Reference link read the beginning and after the step 6, you need to create a custom app and then to create a security policy to allow the new app that you created... during time you will understand how it communicates, how access is done as is written in the tech docs... after that if you want you can submit this to Palo to create an app but 1st you need to do this so the answer is A and D .
upvoted 2 times
Elvenking
2 years, 6 months ago
The question asks for "options" rather than "steps". I guess the question is one of those general knowledge q's.
upvoted 1 times
...
...
Narendragpt
3 years, 7 months ago
A and C are correct
upvoted 1 times
...
tuktuk2020
3 years, 7 months ago
A , C C: since it is a popular (referred in the docs as "commercial") Application , ((Request an App-ID from Palo Alto Networks—If you would like to inspect and control the applications that traverse your network, for any unknown traffic, you can record a packet capture. If the packet capture reveals that the application is a commercial application, you can submit this packet capture to Palo Alto Networks for App-ID development. If it is an internal application, you can create a custom App-ID and/or define an application override policy.)) D: would be right if it an internal or Organization Application https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/manage-custom-or-unknown-applications
upvoted 2 times
...
RinoAlenz
3 years, 8 months ago
Correct A, D C "Create a custom application." unconditional.
upvoted 1 times
...
hpbdcb
3 years, 11 months ago
A & D A: because thats the way to go to reliably identify a custom app PA says: "Create a Custom Application with a signature and attach it to a security policy" D: because you need to see traffic on the wire to create custom patterns matching that new application (otherwise it would be just blocked and you will not be able to create a custom app) PA says: "Create security policies to control unknown applications by unknown TCP, unknown UDP or by a combination of source zone, destination zone, and IP addresses. " So even though a security policy alone (D) will not help but together with A its the way how it works. ref: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/manage-custom-or-unknown-applications#
upvoted 1 times
...
Pradeepan
4 years, 1 month ago
A and c are the answer we can create custom as well give request for app-id creation
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago