Exam nse4_fgt-72 All QuestionsBrowse all questions from this exam
Question 58

Refer to the exhibit.

The exhibit shows the IPS sensor configuration.

If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

    Correct Answer: C, D

    Based on the configuration shown in the exhibit, the sensor will block all attacks aimed at Windows servers as indicated by the 'Block' action for the 'Windows' filter. This means any traffic matching this filter will be blocked. Additionally, the sensor has the action set to 'Monitor' for the 'Microsoft.Windows.iSCSI.Target.DoS' signature, which implies that traffic matching this signature will be allowed to pass through while being monitored, effectively allowing attackers matching this signature. Therefore, the expected actions are that the sensor will block all attacks aimed at Windows servers and allow attackers matching the Microsoft Windows.iSCSI.Target.DoS signature.

Discussion
itashraf

In FortiGate Firewall IPS, the "monitor" action is used to allow the traffic to pass through the firewall but still monitor it for potential threats or policy violations. When an IPS sensor detects an intrusion attempt or violation of a security policy, it can trigger an alert or log the event, providing information for further analysis or action. By using the monitor action instead of the block action, you can allow traffic to continue flowing while still gaining visibility into potential security risks. This can be useful in situations where blocking the traffic might cause operational disruptions or false positives. However, it's important to note that the monitor action does not actively block traffic, so it's recommended to use it in conjunction with other security measures, such as firewalls, antivirus software, and intrusion prevention systems, to ensure comprehensive protection against cyber threats.

chromevandium11Options: CD

I believe the answer should be CD.

efotOptions: CD

Correct Answer is CD

ChiaPet75

Correct Answer is CD When the IPS engine compares traffic with the signatures in each filter, order matters. The Rules are similar to firewall policy matching; the engine evaluates the filters and signatures at the top of the list first, and applies the first match. The engine skips the subsequent filters. FortiGate Security 7.2 StudyGuide p.392

Igor_MioralliOptions: AD

The Right answer is actually A and D, cause there is a catch - the Fortigate is not blocking ALL attacks to windows server cause it is allowing that iSCSI signature to pass through and the matching traffic is indeed set to log

Ney_mediana

I too believe the answer is CD

MalgawOptions: AB

I don't see how C and D can be true simultaneously. The answer is AD.

Mocix

A can not be the correct answer because Packet Logging is disabled for the second signature. So, the answers are C and D.

RianOptions: AB

I rathe say it is A&B. because of detail Microsift.windows.iSCSI.target .Dos and Exempt IP's =0

RewrockOptions: CD

I believe the answer should be CD