A security administrator at a financial firm needs to block all peer-to-peer file-sharing applications for the entire company, but must allow legitimate business use of instant messaging. The administrator wants the least administrative effort and automatic updates of new application signatures. What should the administrator do?
Blocking the Peer-to-Peer category in an Application Control rule automatically covers all current and future peer-to-peer applications without listing them individually. Because the gateway receives automatic signature updates, new P2P apps are blocked without policy changes. This satisfies the requirement to block all P2P while allowing IM, and minimizes administrative effort.
Why this answer
Application Control uses signatures to identify applications regardless of port or protocol. Blocking the Peer-to-Peer category in an Application Control rule immediately blocks all current and future P2P applications, while instant messaging remains allowed. Because signatures are updated automatically, no manual intervention is needed when new P2P apps appear.
Exam trap
The trap here is confusing URL Filtering categories with Application Control categories, and assuming that blocking a URL category will block native P2P applications.