Palo_Alto_Networks
PCNSE7 · Question #181
An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's…
The correct answer is A. Create a custom App-ID and enable scanning on the advanced tab. See the full explanation below for the reasoning.
Question
An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's proprietary accounting application. The administrator wants to reliably identify this traffic as their accounting application and to scan this traffic for threats. Which option would achieve this result?
Options
- ACreate a custom App-ID and enable scanning on the advanced tab.
- BCreate an Application Override policy.
- CCreate a custom App-ID and use the "ordered conditions" check box.
- DCreate an Application Override policy and custom threat signature for the application.
How the community answered
(38 responses)- A82% (31)
- B3% (1)
- C5% (2)
- D11% (4)
Community Discussion
No community discussion yet for this question.