nerdexam
Palo_Alto_Networks

PCNSE7 · Question #181

An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's…

The correct answer is A. Create a custom App-ID and enable scanning on the advanced tab. See the full explanation below for the reasoning.

Question

An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's proprietary accounting application. The administrator wants to reliably identify this traffic as their accounting application and to scan this traffic for threats. Which option would achieve this result?

Options

  • ACreate a custom App-ID and enable scanning on the advanced tab.
  • BCreate an Application Override policy.
  • CCreate a custom App-ID and use the "ordered conditions" check box.
  • DCreate an Application Override policy and custom threat signature for the application.

How the community answered

(38 responses)
  • A
    82% (31)
  • B
    3% (1)
  • C
    5% (2)
  • D
    11% (4)

Community Discussion

No community discussion yet for this question.

Full PCNSE7 Practice