Q2
Single choice
A firewall rule currently allows broad traffic based on ports, and the administrator wants to tighten it by using the applications actually seen over the last several weeks.
Which tool should be used?