PCNSE · Question #719
With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?
The correct answer is C. not-applicable. The answer 'not-applicable' (C) is assigned when App-ID does not apply to the traffic type in question - most commonly for non-TCP/UDP protocols such as ICMP, GRE, or other Layer 4 protocols that carry no application payload for App-ID to inspect. Given the default TCP/UDP…
Question
With the default TCP and UDP settings on the firewall, what will be the identified application in the following session?
Exhibit
Options
- Ainsufficient-data
- Bincomplete
- Cnot-applicable
- Dunknown-tcp
How the community answered
(23 responses)- C96% (22)
- D4% (1)
Explanation
The answer 'not-applicable' (C) is assigned when App-ID does not apply to the traffic type in question - most commonly for non-TCP/UDP protocols such as ICMP, GRE, or other Layer 4 protocols that carry no application payload for App-ID to inspect. Given the default TCP/UDP settings on the firewall and the session shown in the (referenced) graphic, the traffic is a non-TCP/UDP protocol session, so App-ID classification is not applicable. 'incomplete' (B) applies to TCP sessions where the three-way handshake never finished. 'insufficient-data' (A) applies when a TCP/UDP session completed setup but did not carry enough payload bytes for App-ID to make a determination. 'unknown-tcp' (D) applies when a TCP session carried data but App-ID could not match it to a known application signature.
Topics
Community Discussion
No community discussion yet for this question.
