A company is deploying a new internal application that uses a standard web server (HTTPS on port 443) but needs specific security policy enforcement (different from general web browsing) and precise visibility into its usage. App-ID currently identifies this traffic as 'web-browsing'. How can an administrator configure the Palo Alto Networks NGFW (Strata/Prisma SASE) to identify this internal application separately and enable granular policy control?
Correct Answer: B
When App-ID doesn't recognize a custom or specific application, the correct approach for granular identification and policy is to create a custom App-ID signature. Option B correctly describes this process: analyzing the application's traffic for unique patterns and building a custom signature that App-ID can use to identify it separately. Option A uses ports, which is not application-aware. Option C is not possible; built-in App-IDs cannot be directly modified. Option D is for URL categorization, not application identification. Option E is for inspecting content after identification, but doesn't help with the initial App-ID challenge.