Question 1 of 30
A network administrator has developed a custom application signature for a proprietary internal business application, utilizing a specific TCP port and a unique string found within the application\'s data payload for detection. However, the FortiGate Enterprise Firewall 7.0 is consistently misclassifying this internal application\'s traffic as a known, albeit different, third-party application, thereby applying incorrect security policies. Analysis of the FortiGate traffic logs reveals that the misclassification occurs even though the custom signature is configured with a higher precedence than the default signature for the third-party application. What is the most effective technical approach to rectify this misclassification while ensuring that legitimate traffic to the third-party application remains unaffected?
Enhance the custom application signature by incorporating an additional, highly specific detection method, such as a unique byte sequence or a specific header field value, that is exclusively present in the internal application's traffic.
Modify the existing FortiGuard signature for the third-party application to exclude the specific string used in the custom signature, thereby preventing a match.
Reconfigure the custom application signature to utilize a completely different, less common TCP port that is not associated with any known services or applications.
Adjust the signature precedence settings to assign an even higher priority to the custom signature, effectively forcing it to be evaluated before any other potentially overlapping signatures.

Preparing for NSE7_EFW7.0 NSE 7 Enterprise Firewall 7.0? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free