Q23 Single choice Mark for later Which statement about NGFW policy-based application filtering is true? A After the application has been identified, the kernel uses only the Layer 4 header to match the traffic. B The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT. C After IPS identifies the application, it adds an entry to a dynamic ISDB table. D FortiGate will drop all packets until the application can be identified. Correct answer