What are two features of the NGFW policy-based mode? (Choose two.)
What are two features of the NGFW policy-based mode? (Choose two.)
NGFW policy-based mode supports creating applications and web filtering categories directly in the firewall policy, allowing for streamlined policy management without additional configuration of specific profiles. Additionally, NGFW policy-based mode policies support only flow inspection, meaning that all policies in that mode will adhere strictly to flow-based inspection methods, without the option to change to different inspection methods.
A. NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy. C. NGFW policy-based mode policies support only flow inspection. FortiGate Infrastructure 7.2 Study Guide (p.90): "Policy-based mode is actually a new policy mode. You can add applications and web filtering categories directly to a policy without having to first create and configure application control or web filtering profiles." "However, if NGFW mode is Policy-based, then the inspection mode for all policies in that VDOM is always flow and there is no option available in the policy to change it." Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
A, C is correct. Infrastructure guide 7.2, pages 90
The answer are A and C
https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/978598/profile-based-ngfw-vs-policy-based-ngfw