exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 28 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 28
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibit.

Examine the intrusion prevention system (IPS) diagnostic command.
Which statement is correct if option 5 was used with the IPS diagnostic command and the outcome was a decrease in the CPU usage?

  • A. The IPS engine will continue to run in a normal state.
  • B. The IPS engine was unable to prevent an intrusion attack.
  • C. The IPS engine was blocking all traffic.
  • D. The IPS engine was inspecting high volume of traffic.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
toto74500
Highly Voted 1 year, 1 month ago
FortiGate_Security_7.0_Study_Guide page 567 If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode. In this mode, the IPS engine is still running, but it is not inspecting traffic. If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model. If the CPU use remains high after enabling IPS bypass mode, it usually indicates a problem in the IPS engine, which you must report to Fortinet Support.
upvoted 9 times
...
raydel92
Most Recent 4 months, 1 week ago
Selected Answer: D
D. The IPS engine was inspecting high volume of traffic. FortiGate Security 7.2 Study Guide (p.417): "If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode. In this mode, the IPS engine is still running, but it is not inspecting traffic. If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model." Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 1 times
...
geotown
5 months ago
D is the correct answer.
upvoted 1 times
...
velrisan
8 months ago
If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode. In this mode, the IPS engine is still running, but it is not inspecting traffic. If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model. From: Page 416 FortiGate Security 7.2 Study Guide
upvoted 2 times
...
velrisan
8 months ago
Correct is D
upvoted 1 times
...
hamidreza0010
10 months, 2 weeks ago
Selected Answer: D
d is correct
upvoted 1 times
...
Egendary
11 months, 3 weeks ago
Selected Answer: D
the question is about what happened after user, not the function of option 5. if it was asked for the function, Option B will be correct.
upvoted 1 times
...
castaway
12 months ago
Selected Answer: D
If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model.
upvoted 1 times
...
kosta_georgiev
12 months ago
Selected Answer: D
Correct answer is D
upvoted 1 times
...
PoBratsky
1 year ago
Selected Answer: D
toto74500 1 month, 1 week ago FortiGate_Security_7.0_Study_Guide page 567 If there are high-CPU use problems caused by the IPS, you can use the diagnose test application ipsmonitor command with option 5 to isolate where the problem might be. Option 5 enables IPS bypass mode. In this mode, the IPS engine is still running, but it is not inspecting traffic. If the CPU use decreases after that, it usually indicates that the volume of traffic being inspected is too high for that FortiGate model. If the CPU use remains high after enabling IPS bypass mode, it usually indicates a problem in the IPS engine, which you must report to Fortinet Support.
upvoted 2 times
...
hijiri
1 year ago
I guess the answer here is D. it mentioned "was" means before, so it's pertaining that the volume of traffic is high before they disabled the IPS.. causing the CPU usage to decreased. B on the other hand, is not true.. It is able to prevent an intrusion attack and will always be.
upvoted 1 times
...
azizkasmir
1 year, 1 month ago
Selected Answer: B
diagnose test application ipsmonitor 5 <----- This command will help us to bypass the IPS for monitoring) - So less CPU and Memory usage
upvoted 3 times
EliasM
1 year, 1 month ago
So you mean answer D?
upvoted 5 times
...
...
JT20
1 year, 2 months ago
When IPS is bypassed it should reduce CPU usages for traffic inspection. Hence D is more likely a correct answer.
upvoted 2 times
...
Arlequin
1 year, 2 months ago
And Anwser is?
upvoted 1 times
...
TunaSD
1 year, 2 months ago
decrease??
upvoted 1 times
Largadoaki
1 year, 2 months ago
I think it should be "increase"
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago