PSE-PLATFORM · Question #241
An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's…
The correct answer is A. Create a custom App-ID and enable scanning on the advanced tab. Creating a custom App-ID gives the firewall the signatures needed to positively identify the proprietary application through deep packet inspection, and enabling scanning on the advanced tab allows security profiles (Antivirus, Vulnerability, etc.) to be applied - achieving…
Question
An administrator sees several inbound sessions identified as unknown-tcp in the Traffic logs. The administrator determines that these sessions are form external users accessing the company's proprietary accounting application. The administrator wants to reliably identify this traffic as their accounting application and to scan this traffic for threats. Which option would achieve this result?
Options
- ACreate a custom App-ID and enable scanning on the advanced tab.
- BCreate an Application Override policy.
- CCreate a custom App-ID and use the "ordered conditions" check box.
- DCreate an Application Override policy and custom threat signature for the application.
How the community answered
(42 responses)- A83% (35)
- B10% (4)
- C2% (1)
- D5% (2)
Explanation
Creating a custom App-ID gives the firewall the signatures needed to positively identify the proprietary application through deep packet inspection, and enabling scanning on the advanced tab allows security profiles (Antivirus, Vulnerability, etc.) to be applied - achieving both goals simultaneously.
Why the distractors fail:
-
B - An Application Override policy forces the firewall to skip App-ID processing entirely and classify traffic at Layer 4 only, which disables deep packet inspection and therefore disables threat scanning. It's the opposite of what's needed here.
-
C - The "ordered conditions" checkbox in a custom App-ID controls whether signature conditions must match in sequence vs. in any order. It has no effect on enabling threat scanning.
-
D - Combining Application Override with a custom threat signature is self-defeating: Application Override bypasses the content inspection engine, so the firewall never reaches the threat signature scanning stage.
Memory tip: Think "Override = Overrides security too." Any time you see Application Override, remember it trades deep inspection for speed - traffic is classified but not scanned. If the question asks for both identification and scanning, the answer always involves a custom App-ID, never an Application Override.
Topics
Community Discussion
No community discussion yet for this question.