exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 43 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 43
Topic #: 1
[All PCNSE Questions]

An administrator creates a custom application containing Layer 7 signatures. The latest application and threat dynamic update is downloaded to the same NGFW.
The update contains an application that matches the same traffic signatures as the custom application.
Which application should be used to identify traffic traversing the NGFW?

  • A. Custom application
  • B. System logs show an application error and neither signature is used.
  • C. Downloaded application
  • D. Custom and downloaded application signature files are merged and both are used
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hamshoo
Highly Voted 4 years, 7 months ago
Custom applications take precedence over predefined applications when traffic matches both a custom-defined signature and a Palo Alto Networks signature. Accordingly, Traffic logs reflect the custom application name once the new application has been configured. Answer is A
upvoted 28 times
GivemeMoney
3 years ago
straight from here (bottom of page): https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/about-custom-application-signatures.html Thanks hamshoo
upvoted 5 times
...
Eiffelsturm
1 year, 1 month ago
but the question is what SHOULD be used. And the downloaded App should be used for sure
upvoted 2 times
kam1967
11 months, 2 weeks ago
I disagree. If the custom application was created for a specific purpose, the new APP-ID that may happen to also match the custom application could be missing critical additions that have been included in the custom app. For this reason, custom apps should always take precedence over new dynamic apps until the new dynamic apps can be examined to ensure they satisfy all of the requirements that the custom apps satisfies.
upvoted 4 times
...
...
...
luckymuki
Highly Voted 4 years, 7 months ago
A. https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/about-custom-application-signatures.html
upvoted 6 times
...
Yohinar
Most Recent 2 months ago
Selected Answer: C
Question is tricky worded. The firewall will use the custom application if there are both a custom and palo alto defined applicaton available. (Answer A) However the question asks which of both **SHOULD** be used and that is answer C. So answer C is correct for this question.
upvoted 2 times
...
ccie8122
3 months ago
Selected Answer: A
https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/about-custom-application-signatures.html
upvoted 1 times
...
networkingXIV
5 months ago
Selected Answer: A
"Custom applications take precedence over predefined applications when traffic matches both a custom-defined signature and a Palo Alto Networks signature. Accordingly, Traffic logs reflect the custom application name once the new application has been configured."
upvoted 1 times
...
BTSeeYa
6 months ago
Selected Answer: C
Question states the apps are identical in signatures and asks what "should" be used. Wouldn't you want Palo Alto modifying and updating that App-ID in the future for you, as it's threat intel teams gather global information, or do you want to do that yourself for various App-IDs?
upvoted 1 times
...
OmarK
9 months, 3 weeks ago
Selected Answer: C
The correct answer is C. Downloaded application. Here's why: App-ID Prioritization: Palo Alto firewalls prioritize official, vendor-provided application signatures (those downloaded in updates) over custom applications. This ensures that the firewall leverages the most up-to-date and reliable application identification mechanisms. Conflict Resolution: When a conflict occurs, the firewall will automatically use the downloaded application, overriding the custom application to avoid potential misidentification. Maintaining Custom Apps: While custom applications are useful for unique traffic not covered by standard applications, it's important to regularly review them against official App-ID updates to avoid conflicts and potential misidentification of traffic.
upvoted 2 times
...
Marshpillowz
12 months ago
Selected Answer: C
Correct answer is C
upvoted 1 times
...
JoyBoyMx
1 year, 5 months ago
Selected Answer: C
I believe the answer is C, as the question says: "What application SHOULD be used", in that case we should use the downloaded app.
upvoted 1 times
...
lol12
2 years, 2 months ago
Poorly written question. Best practice would be to use the Downloaded application. I think they're asking for which takes precedence so it will be A.
upvoted 6 times
Gngogh
2 years, 1 month ago
i couldn't agree more
upvoted 3 times
...
...
UFanat
2 years, 7 months ago
Selected Answer: A
https://docs.paloaltonetworks.com/pan-os/u-v/custom-app-id-and-threat-signatures/custom-application-and-threat-signatures/about-custom-application-signatures Custom applications take precedence over predefined applications when traffic matches both a custom-defined signature and a Palo Alto Networks signature
upvoted 2 times
...
Jared28
2 years, 11 months ago
C - As others stated which *SHOULD* be used. If you want the best possible Content-ID inspections, best protection, you *should* use the app defined by PA themselves.
upvoted 4 times
...
kerberos
2 years, 11 months ago
"Which application SHOULD be used to identify traffic traversing the NGFW?" is the question. Palo looking for answer C
upvoted 1 times
...
Kane002
3 years, 2 months ago
C. Custom apps take precedence, but the question is saying that PA has released an App-ID for that app, and therefore the custom application should be deleted and the downloaded app should be used instead.
upvoted 1 times
...
jonboy22
3 years, 3 months ago
Custom App Sigs DO take precedance over the default downloaded one. But that is not what this question is asking. The questions asks ,"SHOULD you use..." and to that effect no, you should not use the custom application any longer. Instead, use the Palo Alto created App Sig. Answer is C
upvoted 5 times
...
aadach
3 years, 9 months ago
everything what is custom has the highest priority (prcedence)
upvoted 1 times
...
reyesm
3 years, 11 months ago
A, custom apps take precedence over palo app updates
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago