GSEC Network Security Devices Practice Question
A security engineer is deploying a next-generation firewall (NGFW) at the perimeter of a company's network. The NGFW must enforce security policies based on application identity and user identity, not just IP addresses and ports. The engineer needs to ensure that the firewall can identify applications even when they use non-standard ports or attempt to evade detection by tunneling over HTTP. Which NGFW feature should the engineer configure to meet these requirements?
⚠ Common exam trap
The trap here is assuming that stateful inspection or port-based rules can identify applications, when in fact they cannot see beyond headers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Application-aware filtering with deep packet inspection (DPI)
Application-aware filtering with deep packet inspection is designed to identify applications by analyzing payload content and behavior, not just ports. This enables enforcement of policies based on application identity and detects tunneling or evasion. The other options address different aspects like state tracking, user mapping, or decryption, but none provide the required application identification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User identity awareness via LDAP integration
Why it's wrong here
User identity awareness maps IP addresses to users by querying directory services, enabling policies based on user or group. However, it does not identify applications or inspect payloads. It is a complementary feature but alone cannot detect applications on non-standard ports or tunneling, so it does not satisfy the scenario.
- ✓
Application-aware filtering with deep packet inspection (DPI)
Why this is correct
Application-aware filtering with DPI examines packet payloads beyond headers to identify applications regardless of port or protocol. It can detect tunneling and evasive techniques by analyzing behavioral patterns and signatures. This directly addresses the requirement to enforce policies based on application identity and to handle non-standard ports and HTTP tunneling.
- ✗
SSL/TLS decryption with certificate pinning
Why it's wrong here
SSL/TLS decryption allows inspection of encrypted traffic, but certificate pinning can prevent decryption. Moreover, decryption alone does not provide application identification; it must be combined with DPI or application signatures. This option addresses encryption, not application identification on non-standard ports, so it is insufficient.
- ✗
Stateful packet inspection (SPI) with port-based rules
Why it's wrong here
SPI tracks connection state but relies on port numbers and protocol headers to classify traffic. It cannot identify applications that use non-standard ports or tunnel over HTTP because it does not inspect payload content. Therefore, it fails to meet the requirement for application identity enforcement.
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.