A company has an application signature for an internal ERP system that uses a proprietary protocol over TCP port 4444. The ERP traffic is sometimes misidentified as unknown-tcp. Which App-ID mechanism should be used to improve identification without affecting the default App-ID engine?
A custom application with a data pattern matches the proprietary protocol's payload signature on port 4444, giving deterministic identification. This adds a signature without altering the predefined App-ID engine, satisfying the constraint of not affecting default identification.
Why this answer
Creating a custom application with a data pattern (signature) allows the firewall to identify the ERP traffic based on its unique payload characteristics, without overriding or disabling the default App-ID engine. This approach uses a custom App-ID signature that matches the proprietary protocol's data pattern, ensuring accurate identification while the default engine continues to process other traffic normally.
Exam trap
The trap here is that candidates confuse 'application override' (which bypasses App-ID) with 'custom application signature' (which enhances App-ID), leading them to choose options that disable inspection rather than improve it.
How to eliminate wrong answers
Option A is wrong because a port-based application override statically maps all traffic on TCP 4444 to a specific application, which bypasses the default App-ID engine entirely and prevents it from learning or updating signatures for that port. Option B is wrong because SSL decryption is irrelevant for a proprietary protocol over TCP that does not use SSL/TLS encryption; it would not help identify the application and could introduce unnecessary overhead. Option D is wrong because an application override allows traffic without any App-ID inspection, which defeats the purpose of improving identification and can permit unwanted or malicious traffic to pass unchecked.