Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard

A security technician needs to configure a security policy rule that allows internal users to access an external web server using a specific custom application that runs on TCP port 9000. However, the application is not identified by any existing App-ID signature. To ensure the firewall still identifies this as a unique application and applies specific security profiles, what is the most appropriate step?

  1. ACreate a custom URL category for the web server's domain and apply it to the rule.
  2. BCreate a custom service object for TCP 9000 and use 'any' as the application.
  3. CCreate a Custom App-ID for the application and use 'application-default' as the service.
  4. DUse the built-in 'web-browsing' App-ID and a custom service object for TCP 9000.
Show answer & explanation

Correct answer: C. Create a Custom App-ID for the application and use 'application-default' as the service.

When an application is truly custom and not identified by existing App-IDs, creating a Custom App-ID is the correct approach. This allows the firewall to identify the unique application signature, making it a first-class citizen in the policy. Pairing it with 'application-default' ensures that if the custom app behaves like a known protocol (e.g., HTTP), the firewall can still apply relevant security profiles.

Why the other options are wrong

  • A. A custom URL category helps control access to specific websites but does not define or identify a unique application running on a particular port.
  • B. Using 'any' as the application combined with a custom service object bypasses App-ID entirely, providing only port-based control and losing all application-level visibility and security profile enforcement.
  • D. Using 'web-browsing' would only work if the custom application was indeed web-browsing (HTTP/HTTPS). If it's a proprietary application, 'web-browsing' would misidentify or fail to identify it, and a custom service object would again limit App-ID's effectiveness.

Custom App-ID

A Custom App-ID is created on Palo Alto Networks firewalls to identify proprietary or unique applications that are not recognized by the built-in App-ID database. It allows for granular policy enforcement for specific, non-standard applications.

  • Identifies proprietary or unknown applications.
  • Can be based on signatures, ports, or protocol headers.
  • Enables application-level control for unique traffic.

Memory trick: New App, New App-ID.

More Security Policy Configuration questions