Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSE topic 1 question 35 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 35
Topic #: 1
[All PCNSE Questions]

A customer has an application that is being identified as unknown-tcp for one of their custom PostgreSQL database connections.
Which two configuration options can be used to correctly categorize their custom database application? (Choose two.)

  • A. Application Override policy.
  • B. Security policy to identify the custom application.
  • C. Custom application.
  • D. Custom Service object.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️
Reference:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clc6CAC

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
dhanala
Highly Voted 3 years, 9 months ago
B and C is correct, if we are choosing C custom application then in the security policy we need to choose Custom Application.
upvoted 20 times
GivemeMoney
2 years, 3 months ago
Yep, B and C https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/manage-custom-or-unknown-applications.html
upvoted 4 times
Gabranch
5 months ago
Disagree - Question is how to correctly categorize the applicaiton. Security Policy is how to deal with an unknown app - as in how to allow it despite having no app-id for it. It does not deal with categorizing the app.
upvoted 1 times
...
...
datz
1 year, 10 months ago
B. Security policy to identify the custom application. B is there to identify customer app-ID? as advised it is custom so allowing traffic is not issue to find out what APP-ID is inside a Traffic Must be A and C
upvoted 2 times
...
...
tester12
Highly Voted 4 years, 6 months ago
Answer is A and C
upvoted 10 times
...
gradski
Most Recent 2 weeks, 2 days ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/app-id/manage-custom-or-unknown-applications
upvoted 1 times
...
428cd48
4 weeks ago
on 3/22 exam
upvoted 1 times
...
Mar_a_Lagoon
1 month, 1 week ago
Selected Answer: AC
AC, refer to the other replies. Secuity policy will never id anything
upvoted 1 times
...
SH_
2 months, 1 week ago
Selected Answer: AC
security policy doesn't identify apps, app-id does. create a custom app AND/OR use an app override policy to identify the app based on traffic using it. THEN consult the security policy to figure out whether to block or allow the traffic.
upvoted 1 times
...
Marshpillowz
2 months, 3 weeks ago
Selected Answer: AC
A, C correct answer here
upvoted 1 times
...
JRKhan
3 months, 1 week ago
Selected Answer: AC
A & C are correct. Security policy allows or denies the traffic, doesnt categorise the application. The two ways you can categorise an application is to define a custom App or use Application override policy where you will still need to define the application ports, IP addresses, zones etc. to identify the application. Application override is not recommended however and should only be used as a temporary workaround while the work is going on to define a custom app for the same traffic.
upvoted 2 times
...
onkel_andi
4 months, 2 weeks ago
Selected Answer: AC
A and C correct
upvoted 2 times
...
dorf05
4 months, 2 weeks ago
Selected Answer: BC
I think 'A' is wrong because..For internal applications and applications for which there is no App-ID, create custom applications to gain layer 7 visibility into traffic. Don’t use Application Override policy because it bypasses layer 7 processing and threat inspection. The use cases for Application Override are unusual situations with SMB or SIP traffic.
upvoted 1 times
...
Nina93523
4 months, 2 weeks ago
Selected Answer: BC
-Manage Custom or Unknown Applications Create a Custom Application with a signature and attach it to a security policy, or create a custom application and define a custom timeout. Avoid creating Application Override
upvoted 1 times
...
gc999
4 months, 4 weeks ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/manage-custom-or-unknown-applications#:~:text=Create%20a%20Custom%20Application%20with%20a%20signature%20and%20attach%20it%20to%20a%20security%20policy%2C%20or%20create%20a%20custom%20application%20and%20define%20a%20custom%20timeout.%20Avoid%20creating%20Application%20Override
upvoted 2 times
...
skullomania
5 months, 1 week ago
Selected Answer: AC
Stop inventing people. You don't create a security policy to identify the custom application. Correct options are A and C. I'm a PCNSE engineer since 2017 and PCNSC since 2019.
upvoted 3 times
...
Xuzi
5 months, 2 weeks ago
The following choices are available to handle unknown applications: Create security policies to control unknown applications by unknown TCP, unknown UDP or by a combination of source zone, destination zone, and IP addresses. Create a Custom Application with a signature and attach it to a security policy, or create a custom application and define a custom timeout. Avoid creating Application Override policies because they bypass layer 7 application processing and threat inspection, and use less secure stateful layer 4 inspection instead. Instead, use custom timeouts so that you can control and inspect the application traffic at layer 7.
upvoted 1 times
...
Micutzu
6 months, 1 week ago
Selected Answer: AC
A and C are correct.
upvoted 1 times
...
[Removed]
6 months, 2 weeks ago
Selected Answer: AC
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clc6CAC
upvoted 1 times
...
cajarquin
6 months, 3 weeks ago
Selected Answer: AC
Answer is A and C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...