exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 35 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 35
Topic #: 1
[All PCNSE Questions]

A customer has an application that is being identified as unknown-tcp for one of their custom PostgreSQL database connections.
Which two configuration options can be used to correctly categorize their custom database application? (Choose two.)

  • A. Application Override policy.
  • B. Security policy to identify the custom application.
  • C. Custom application.
  • D. Custom Service object.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
dhanala
Highly Voted 4 years, 6 months ago
B and C is correct, if we are choosing C custom application then in the security policy we need to choose Custom Application.
upvoted 21 times
GivemeMoney
2 years, 12 months ago
Yep, B and C https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/manage-custom-or-unknown-applications.html
upvoted 4 times
Gabranch
1 year, 1 month ago
Disagree - Question is how to correctly categorize the applicaiton. Security Policy is how to deal with an unknown app - as in how to allow it despite having no app-id for it. It does not deal with categorizing the app.
upvoted 2 times
...
...
datz
2 years, 7 months ago
B. Security policy to identify the custom application. B is there to identify customer app-ID? as advised it is custom so allowing traffic is not issue to find out what APP-ID is inside a Traffic Must be A and C
upvoted 2 times
...
...
tester12
Highly Voted 5 years, 3 months ago
Answer is A and C
upvoted 10 times
...
CarlosDV06
Most Recent 1 week, 1 day ago
Selected Answer: AC
Ok, so you should avoid using app overrides since it bypasses app-id analysis, instead use a custom application with a defined signature. However, you can categorize an application: 1. Application override - It matches your application using source and destination address, ports, etc. 2. Custom application - You can define a custom application with a admin-defined signature for the app id engine to match. You would have to create a security policy rule using this custom app to allow the traffic, but you won't identify the application with a security policy rule, to identify the app's patterns and create a signature you should perform a pcap. 3. Creating an app id categorization through web, which could be deployed as a new app id in the third week of any month.
upvoted 1 times
...
Pretorian
2 months, 2 weeks ago
Selected Answer: AC
A and C are the correct answers. The below is directly from the PANW Firewall help (?): "Policies > Application Override To change how the firewall classifies network traffic into applications, you can specify application override policies. For example, if you want to control one of your custom applications, an application override policy can be used to identify traffic for that application according to zone, source and destination address, port, and protocol. If you have network applications that are classified as “unknown,” you can create new application definitions for them (refer to Defining Applications)." Seems conclusive 👍
upvoted 2 times
...
ccie8122
2 months, 4 weeks ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/app-id/manage-custom-or-unknown-applications "Create a Custom Application with a signature and attach it to a security policy, or create a custom application and define a custom timeout. Avoid creating Application Override policies because they bypass layer 7 application processing"
upvoted 2 times
...
apiloran
3 months, 3 weeks ago
Selected Answer: BC
B & C Create a Custom Application with a signature and attach it to a security policy, or create a custom application and define a custom timeout. Avoid creating Application Override policies because they bypass layer 7 application processing and threat inspection, and use less secure stateful layer 4 inspection instead. Instead, use custom timeouts so that you can control and inspect the application traffic at layer 7.
upvoted 1 times
...
eaakgul
7 months, 3 weeks ago
Correct answer is A & C
upvoted 1 times
...
1f2c588
8 months, 1 week ago
A&C are correct. Application Override to baypass the App-ID and the custom application to indentfie the applications, (then the tow actions to catigorize the applicaitonà)
upvoted 1 times
...
0d2fdfa
8 months, 1 week ago
Selected Answer: AC
Which two configuration options can be used to correctly categorize It is about categorization and not the implementation.
upvoted 2 times
...
gradski
9 months, 2 weeks ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/11-1/pan-os-admin/app-id/manage-custom-or-unknown-applications
upvoted 2 times
...
428cd48
9 months, 4 weeks ago
on 3/22 exam
upvoted 2 times
...
Mar_a_Lagoon
10 months, 1 week ago
Selected Answer: AC
AC, refer to the other replies. Secuity policy will never id anything
upvoted 1 times
...
SH_
11 months, 1 week ago
Selected Answer: AC
security policy doesn't identify apps, app-id does. create a custom app AND/OR use an app override policy to identify the app based on traffic using it. THEN consult the security policy to figure out whether to block or allow the traffic.
upvoted 2 times
...
Marshpillowz
11 months, 3 weeks ago
Selected Answer: AC
A, C correct answer here
upvoted 1 times
...
JRKhan
1 year ago
Selected Answer: AC
A & C are correct. Security policy allows or denies the traffic, doesnt categorise the application. The two ways you can categorise an application is to define a custom App or use Application override policy where you will still need to define the application ports, IP addresses, zones etc. to identify the application. Application override is not recommended however and should only be used as a temporary workaround while the work is going on to define a custom app for the same traffic.
upvoted 2 times
...
onkel_andi
1 year, 1 month ago
Selected Answer: AC
A and C correct
upvoted 2 times
...
dorf05
1 year, 1 month ago
Selected Answer: BC
I think 'A' is wrong because..For internal applications and applications for which there is no App-ID, create custom applications to gain layer 7 visibility into traffic. Don’t use Application Override policy because it bypasses layer 7 processing and threat inspection. The use cases for Application Override are unusual situations with SMB or SIP traffic.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago