問題文
During a design review, an engineer is asked what the firewall examines in order to name the application carried in a session. Which description matches how application identification works?
選択肢
- It examines the payload as the session proceeds, applies signatures and protocol decoders, and can revise its earlier conclusion when later packets reveal a different application.
- It counts the number of bytes per second and matches the rate against a table of known application profiles.
- It reads only the first packet of the session, because the application must declare itself before any data is exchanged.
- It queries an external directory with the source address and receives the name of the application that the user is entitled to run, and it then compares that name with the traffic so that unexpected applications are reported for review.