exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 85 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 85
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibit.

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.

An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.



What are two solutions for satisfying the requirement? (Choose two.)

  • A. Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.
  • B. Configure a web override rating for download.com and select Malicious Websites as the subcategory.
  • C. Set the Freeware and Software Downloads category Action to Warning.
  • D. Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
raydel92
Highly Voted 1 year, 3 months ago
Selected Answer: BD
B. Configure a web override rating for download.com and select Malicious... D. Configure a static URL filter entry for download.com with Type and Action... FortiGate Security 7.2 Study Guide (p.268-269): "If you want to make an exception, for example, rather than unblock access to a potentially unwanted category, change the website to an allowed category. You can also do the reverse. You can block a website that belongs to an allowed category." "Static URL filtering is another web filter feature. Configured URLs in the URL filter are checked against the visited websites. If a match is found, the configured action is taken. URL filtering has the same patterns as static domain filtering: simple, regular expressions, and wildcard." A. Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com... (incorrect because you still allow root domain) Download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 6 times
...
Ben61
Most Recent 5 months, 1 week ago
Selected Answer: BD
Tested on 7.0.14 : B : OK D: OK A : NO, fortigate can't resolve *.download.com, but with download.com it's works
upvoted 1 times
...
Bungee75
6 months, 1 week ago
Selected Answer: AD
Options B and C do not meet the requirement because they do not provide fine control over specific websites. Option B involves overriding the rating by classifying the website as Malicious, which might not be the correct classification and would not block the site. Option C sets the entire category to Warning, which would only issue a warning to users and would not block access to download.com.
upvoted 1 times
Bungee75
6 months, 1 week ago
And I tested A and D on my FGT and solution works.
upvoted 1 times
...
...
ronia
10 months, 3 weeks ago
Selected Answer: AD
AD is valid
upvoted 1 times
...
GeniusA
1 year ago
BD is a valid response
upvoted 1 times
...
AMK2ENG
1 year ago
B. Configure a web override rating for download.com and select Malicious Websites as the subcategory. D. Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
upvoted 1 times
...
Jumpy007
1 year, 3 months ago
Selected Answer: BD
FortiGate Security 7.2 Study Guide (p.268-269)
upvoted 1 times
...
jeroenptrs93
1 year, 4 months ago
Selected Answer: BD
I don't think it's A because of "object for *.download.com" you can still reach it with https://download.com. The *. don't exclude apply on https://download.com iirc
upvoted 2 times
...
[Removed]
1 year, 4 months ago
Selected Answer: BD
Such as Brazillian guys says "Confia no pai!..." Correct answers: BD
upvoted 1 times
...
darkstar15
1 year, 4 months ago
Hola creo B y D son correctas: B: If you want to make an exception, for example, rather than unblock access to a potentially unwanted category, change the website to an allowed category. You can also do the reverse. You can block a website that belongs to an allowed category. Remember that changing categories does not automatically result in a different action for the website. This depends on the settings within the web filter profile. en la imagen nos muestra una categoria como denegada dentro del perfil (malicious Websites).
upvoted 1 times
...
Tedmus
1 year, 4 months ago
Selected Answer: BD
I would go for B & D. C is definitivly wrong, and A is to complicated to achieve this. NSE4-SEC Page 268+269 for reference. Even the "wildcard" statement should not be a problem.
upvoted 4 times
...
alessandro2039
1 year, 4 months ago
Could anyone tell me why B,D isnt the correct answer? I would never create a new firewall policy to block a single site but i have many times in the past used web override ratings to block or unblock sites while leaving the rest intact.
upvoted 1 times
...
pramodbs
1 year, 4 months ago
My vote is AB
upvoted 1 times
...
link13
1 year, 4 months ago
I think D is incorrect because the type should be "simple" not "wildcard". My vote is A & B.
upvoted 1 times
...
e359166
1 year, 5 months ago
Selected Answer: AD
FortiGate Security 7.2 study guide A. web filter profiles flow based Page 263 D. URL Filtering Page 269
upvoted 4 times
Bungee75
6 months, 1 week ago
My first guess were ABD ... B would work, but it's not kosher. A Definetly work, as *.download.com FQDN will resolve IP addresses and regardles of protocol it will be blocked. D: Static URL filtering is normal thing to do (unless your license is expired, then use A)
upvoted 1 times
...
...
TommyMaru
1 year, 5 months ago
I think B should work.
upvoted 1 times
...
GANGA2021
1 year, 5 months ago
Why not B?
upvoted 2 times
Javier2021
1 year, 5 months ago
I believe it is because the profile is in Flow-based mode.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago