exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 37 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 37
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibit.

The exhibit shows the IPS sensor configuration.
If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will block all attacks aimed at Windows servers.
  • B. The sensor will gather a packet log for all matched traffic.
  • C. The sensor will allow attackers matching the NTP.Spoofed.KoD.DoS signature.
  • D. The sensor will reset all connections that match these signatures.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
raydel92
4 months, 1 week ago
Selected Answer: AC
Correct: A. The sensor will block all attacks aimed at Windows servers. C. The sensor will allow attackers matching the NTP.Spoofed.KoD.DoS signature. Incorrect: B. The sensor will gather a packet log for all matched traffic. D. The sensor will reset all connections that match these signatures. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 1 times
...
geotown
5 months ago
Answer is A & C.
upvoted 1 times
...
sb_alves
8 months, 1 week ago
Selected Answer: AC
A and C
upvoted 1 times
...
dude9
10 months ago
Why isnt packet logging for matched traffic correct also?
upvoted 1 times
...
BUZOMD
10 months, 1 week ago
Selected Answer: AC
Check on Fortigate Security Study Guide Page 532 ==> In the event of a false-positve outbreak, you can add the tiggered signature as an individual signature and set the action to monitor. This allows you to monitor the signature events using IPS log, while inbestigating the false-positive issue
upvoted 1 times
...
Carlos_lazaro
11 months, 3 weeks ago
Do you any comment?
upvoted 1 times
Dylon
10 months, 3 weeks ago
Any comment do you?
upvoted 1 times
...
...
toto74500
1 year, 1 month ago
Selected Answer: AC
you have to read the field like a firewall policy; first match first action. Here NTP.spoofed.Kod.DOS is read before windows IPS protection and will be monitored, then windows server is protected for the rest
upvoted 3 times
...
ZBOO
1 year, 2 months ago
Selected Answer: AC
Given answer is correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago