exam questions

Exam NSE4_FGT-7.0 All Questions

View all questions & answers for the NSE4_FGT-7.0 exam

Exam NSE4_FGT-7.0 topic 1 question 36 discussion

Actual exam question from Fortinet's NSE4_FGT-7.0
Question #: 36
Topic #: 1
[All NSE4_FGT-7.0 Questions]

Refer to the exhibit.

Review the Intrusion Prevention System (IPS) profile signature settings.
Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. Traffic matching the signature will be silently dropped and logged.
  • B. The signature setting uses a custom rating threshold.
  • C. The signature setting includes a group of other signatures.
  • D. Traffic matching the signature will be allowed and logged.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PSETGS
Highly Voted 1 year, 1 month ago
Selected Answer: A
"pass" is only default action To explain this: the Pass action on the specific signature would only be chosen, if the Action (on the top) was set to Default. But instead its set to Block, so the action is will be to block and drop.
upvoted 26 times
chromevandium11
1 year ago
Great explanation and thanks for the clarification!
upvoted 3 times
...
...
raydel92
Most Recent 4 months, 1 week ago
Selected Answer: A
A. Traffic matching the signature will be silently dropped and logged. FortiGate Security 7.2 Study Guide (p.394): "Select Allow to allow traffic to continue to its destination. Select Monitor to allow traffic to continue to its destination and log the activity. Select Block to silently drop traffic matching any of the signatures included in the entry. Select Reset to generate a TCP RST packet whenever the signature is triggered. Select Default to use the default action of the signatures." "If you enable Packet logging, FortiGate saves a copy of the packet that matches the signature." Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 2 times
...
geotown
5 months ago
correct answer is A from exam.
upvoted 1 times
...
Net_Boy_26
10 months ago
Selected Answer: A
Answer A reference http://docs.fortinet.com/document/fortigate/6.0.0/handbook/240599/application-control
upvoted 1 times
...
DriftandLuna
10 months, 1 week ago
Answer is A, i thought it was D but PSETGS's explanation is correct.
upvoted 2 times
...
aleexkvs
12 months ago
Packet Logging is enabled. It doesnt generate log when dropping ?
upvoted 1 times
...
Fabio6699
1 year ago
Selected Answer: A
The action overrides the default action
upvoted 2 times
...
toto74500
1 year, 1 month ago
Selected Answer: A
When you create a new entry to add signatures or filters, you can select the action by clicking Action. Select Allow to allow traffic to continue to its destination. Select Monitor to allow traffic to continue to its destination and log the activity. Select Block to silently drop traffic matching any of the signatures included in the entry. Select Reset to generate a TCP RST packet whenever the signature is triggered. Select Default to use the default action of the signatures. Quarantine allows you to quarantine the attacker’s IP address for a set duration. You can set the quarantine duration to any number of days, hours, or minutes. If you enable Packet logging, FortiGate saves a copy of the packet that matches the signature.
upvoted 2 times
...
DB_BD
1 year, 1 month ago
Selected Answer: D
Hello, i think its also D. See this Article from Fortinet: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Exempting-Allow-one-single-IPS-signature-for-IPS/ta-p/192671
upvoted 1 times
Virutas
1 year, 1 month ago
From Security guide, pag 529. "Select Default to use the default action of the signatures.". So in this question the action "Block" overrides the action "Pass" of the particular signature.
upvoted 3 times
...
...
Omar1609
1 year, 2 months ago
Selected Answer: D
Could you review this answer? because the FTP.Login.Failed signature has the action "Pass" I think that correct answer ir D.
upvoted 1 times
...
Israelq
1 year, 2 months ago
Respuesta A, Guia de Seguridad Fortigate V 7.0 Página: 534.
upvoted 3 times
BUZOMD
10 months, 1 week ago
Es correcto lo que indica Israelq => "Block to the silently" drop traffic matching any signatures included in the entry. "Packet logging", Fortigate saves a copy of the packet that matches the signature.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago