exam questions

Exam FCP_FGT_AD-7.4 All Questions

View all questions & answers for the FCP_FGT_AD-7.4 exam

Exam FCP_FGT_AD-7.4 topic 1 question 14 discussion

Actual exam question from Fortinet's FCP_FGT_AD-7.4
Question #: 14
Topic #: 1
[All FCP_FGT_AD-7.4 Questions]

Refer to the exhibit, which shows the IPS sensor configuration.

If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will gather a packet log for all matched traffic.
  • B. The sensor will reset all connections that match these signatures.
  • C. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature.
  • D. The sensor will block all attacks aimed at Windows servers.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
0d6e481
Highly Voted 2 months, 1 week ago
Selected Answer: CD
How can A be a correct answer when the packet logging is enabled only for the iSCSI attack and disabled for the Windows attacks?
upvoted 9 times
...
rigonet
Most Recent 1 day, 14 hours ago
Selected Answer: AC
Correct Answers: A and C Explanation of Each Option: A. The sensor will gather a packet log for all matched traffic. Correct. The "Microsoft.Windows.iSCSI.Target.DoS" signature has packet logging enabled, so matched traffic will be logged. B. The sensor will reset all connections that match these signatures. Incorrect. The configuration does not indicate resetting connections, as the action for the "iSCSI" signature is set to "Monitor." C. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. Correct. The action for this signature is set to "Monitor," meaning traffic matching this signature is allowed but logged. D. The sensor will block all attacks aimed at Windows servers. Incorrect. The signature for "iSCSI" is explicitly set to "Monitor," so it will not block this attack. Conclusion: The sensor will log traffic (A) for matched signatures and allow traffic (C) for the monitored "iSCSI" signature.
upvoted 2 times
...
sxcap
1 week, 4 days ago
Selected Answer: CD
A is incorrect because there is no log enabled to blocked packets B is incorrect because iSCI packets are allowed C is correct because iSCI packets are allowed D is correct because all other windows server attacks will be blocked
upvoted 3 times
...
Booma1234
2 weeks ago
Selected Answer: AC
A and C are the only way mes it could be when you look closely at it.
upvoted 1 times
...
evdw
3 weeks, 6 days ago
Selected Answer: AC
Correct answer is A,C
upvoted 2 times
...
evdw
3 weeks, 6 days ago
Microsoft.Windows.iSCSI.Target.DoS is allowed, so not all attacks to windows are blocked. And when hitting the Microsoft.Windows.iSCSI.Target.DoS attack, it is getting logged
upvoted 1 times
...
vuhidus
1 month ago
Selected Answer: CD
I believe it's C & D
upvoted 1 times
...
Charly0710
1 month, 1 week ago
A and C. D cannot be for the following reason: "When the IPS engine compares traffic with the signatures in each filter, order matters. The rules are similar to firewall policy matching; the engine evaluates the filters and signatures at the top of the list first, and applies the first match. The engine skips subsequent filters". Pag 243 Fortinate Administrator Study Guide
upvoted 3 times
...
262cfa1
1 month, 1 week ago
Selected Answer: AD
A: The sensor will gather a paket log and D: then block traffic aimed to win srv.
upvoted 1 times
262cfa1
1 month, 1 week ago
I agree with your analysis!
upvoted 1 times
...
...
s4mu3l007
1 month, 2 weeks ago
C and D are correct
upvoted 1 times
...
felixliao
1 month, 2 weeks ago
Selected Answer: CD
C and D
upvoted 2 times
...
marcovinicius4
1 month, 2 weeks ago
Selected Answer: CD
C and D
upvoted 2 times
...
0d6e481
1 month, 3 weeks ago
A. The sensor will gather a packet log for all matched traffic. Packet logging for the first line is enabled but it's disabled for the second line (OS Windows). Please explain how can A be a correct answer.
upvoted 2 times
...
CharlieS8
1 month, 4 weeks ago
If you will research about the signature. it actually targets the server. So D is not true because the way the filter works is from top to bottom. thus, allowing the Signature above to pass through without blocking it. So, if B and D is incorrect the only remaining answer is A and C
upvoted 3 times
CharlieS8
1 month, 4 weeks ago
https://learn.microsoft.com/en-us/windows-server/storage/iscsi/iscsi-target-server
upvoted 1 times
...
...
6f7d62a
2 months ago
Selected Answer: AC
A and C, the key is that everything related to windows OS will be blocked, not specifically windows servers, “server” is just a name.
upvoted 4 times
...
DavidCA2024
2 months, 2 weeks ago
Selected Answer: AC
A (monitor & block generates log for matching traffic) C (order matters and this is also an atack aimed at windows servers, and because this, D is incorrect)
upvoted 4 times
...
fab1ccb
3 months ago
Selected Answer: AD
A and D are correct because is enabled on the output the monitor and logging for sessions, and the action for windows server/client which will match the signature is block
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago