フリー問題

Palo Alto Networks Certified Network Security Professional のフリー問題 3 / 20 問目

問題文

A retailer allows outbound TCP 443 for all users so that staff can reach cloud tools. An audit finds that a file-sharing service and a remote desktop tool both reach the internet over that same port. Why does application-layer inspection address this finding when a port-based rule cannot?

選択肢

  1. It identifies the application from the content of the session rather than from the port and protocol, so two applications sharing one port are told apart.
  2. It blocks every session that does not use the port officially registered for that application, so the ambiguity of shared ports disappears once every application is pinned to its own registered number.
  3. It relies on the certificate name presented by the server, which is unique per application and therefore enough to separate them by name alone without any inspection of the encrypted session payload.
  4. It rewrites the destination port of each session to a unique value so that each application can be matched by a separate port-based rule afterward, which keeps the existing port-based rule base usable while adding per-application precision.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。