Made an account just to tell you guys the correct answer is A.
Application is first identified as SSL on port 443, then decrypted, then identified as web-browsing on port 443. Application identification changes due to app shift, but the port number doesn't!
Correct answer is A.
no, since ssl forward proxy is in place. ssl is getting "decrypted", and traffic is identified as web-browsing. app-id will be ssl initially but *shift*!
A. web-browsing and 443
Explanation:
When traffic to https://www.microsoft.com is decrypted by a Palo Alto Networks firewall:
Application: The decrypted traffic is classified as web-browsing (since it’s HTTP/HTTPS web traffic).
Service/Port: The original encrypted traffic uses port 443 (HTTPS), and this port is retained in the logs even after decryption.
Why Not the Other Options?
B. SSL and 80 → Incorrect. Port 80 is for HTTP (unencrypted), and "SSL" is not the app name after decryption.
C. SSL and 443 → "SSL" is the application name before decryption. Once decrypted, it becomes web-browsing.
D. web-browsing and 80 → Port 80 is for HTTP, but Microsoft’s site uses HTTPS (port 443).
Key Notes:
Before decryption: App = ssl, Port = 443.
After decryption: App = web-browsing, Port = 443 (retained from original flow).
Thus, A is correct for decrypted packets.
It is definitely "A". Just looked it up on a firewall:
show session all filter source 192.168.0.***
--------------------------------------------------------------------------------
ID Application State Type Flag Src[Sport]/Zone/Proto (translated IP[Port])
Vsys Dst[Dport]/Zone (translated IP[Port])
--------------------------------------------------------------------------------
20714 web-browsing ACTIVE FLOW *NS 192.168.0.***[63325]/abc00/6 (***.***.***.***[35661])
vsys1 104.208.16.90[443]/def00 (104.208.16.90[443])
and looking more closely:
show session id 20714
Session 20714
c2s flow:
source: 192.168.0.*** [abc00]
dst: 104.208.16.90
proto: 6
sport: 63325 dport: 443
...
application : web-browsing
...
tracker stage firewall : TCP FIN
tracker stage l7proc : proxy timer expired
end-reason : tcp-fin
This section is not available anymore. Please use the main Exam Page.PCNSE Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Pacheco
Highly Voted 4 years, 3 months agokerberos
3 years, 5 months agomannyvic
Highly Voted 5 years, 2 months agokraut
3 years, 8 months agoNico1973
Most Recent 2 months, 2 weeks agoNazmulHossain
5 months, 1 week ago0d2fdfa
7 months, 1 week agoMarshpillowz
10 months, 3 weeks agoWoody
2 years agofireb
2 years, 5 months agoMeko
2 years, 6 months agoUFanat
2 years, 6 months agoWilliam88
2 years, 6 months agodatz
2 years, 6 months agoElvenking
2 years, 8 months agoAbuHussain
2 years, 8 months agoSyn1337
2 years, 9 months agokam1967
3 years, 1 month agorenzanjo
3 years, 1 month agoBighize
3 years agoRJ45TP
3 years agoBreyarg
2 years, 12 months agoLaithFraij
1 year, 9 months agoevdw
3 years, 7 months ago