A security engineer is troubleshooting why a web application is not being identified correctly. The firewall shows the session as 'ssl' instead of the specific application. The engineer has verified that the traffic is using TLS 1.3. What is the most likely reason for the misidentification?
Without SSL decryption, the firewall cannot inspect the encrypted payload and can only identify the traffic as ssl based on the port or protocol. To identify the specific application inside TLS, the firewall must decrypt the traffic. This is especially true for TLS 1.3, where more of the handshake is encrypted, making it harder to identify the application without decryption.
Why this answer
SSL decryption is required to inspect encrypted traffic and identify the application inside. Without decryption, the firewall can only classify the session as ssl based on the protocol, not the specific application. This is particularly relevant for TLS 1.3, where more of the handshake is encrypted, making decryption even more critical for accurate App-ID.
Exam trap
The trap here is assuming that App-ID can identify applications inside encrypted traffic without decryption, but encryption hides the application signatures, so only ssl is identified.