During a security audit, it is discovered that a custom application signature matches too broadly, causing benign traffic to be classified as the custom app. What change should be made to narrow the signature?
A data pattern filter constrains the signature to a distinctive payload string, so matching requires the specific byte sequence rather than broad context alone. This narrows detection to the intended application, preventing benign sessions that merely resemble the app from being classified as the custom app.
Why this answer
Adding a data pattern filter allows the custom App-ID signature to match on a specific payload string or byte sequence, which narrows the scope of traffic classified as that application. Without a data pattern, the signature may rely solely on IP protocol, port, or other broad criteria, causing false positives. By requiring a unique payload signature, only traffic containing that exact data pattern is identified as the custom application.
Exam trap
The trap here is that candidates mistakenly think expanding port ranges or removing protocol fields will narrow the signature, when in fact those actions broaden the match criteria and worsen false positives.
How to eliminate wrong answers
Option A is wrong because removing the protocol field would make the signature even broader, potentially matching any IP traffic regardless of protocol (TCP, UDP, etc.), increasing false positives. Option B is wrong because using a wider port range and removing data patterns would expand the matching criteria, making the signature less specific and more likely to misclassify benign traffic. Option D is wrong because expanding the port range includes more traffic, which would broaden the signature and worsen the over-matching issue, not narrow it.