exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 58 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 58
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibit.
The exhibit shows the IPS sensor configuration.

If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

  • A. The sensor will gather a packet log for all matched traffic.
  • B. The sensor will reset all connections that match these signatures.
  • C. The sensor will block all attacks aimed at Windows servers.
  • D. The sensor will allow attackers matching the Microsoft Windows.iSCSI.Target.DoS signature.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
itashraf
Highly Voted 1 year, 8 months ago
In FortiGate Firewall IPS, the "monitor" action is used to allow the traffic to pass through the firewall but still monitor it for potential threats or policy violations. When an IPS sensor detects an intrusion attempt or violation of a security policy, it can trigger an alert or log the event, providing information for further analysis or action. By using the monitor action instead of the block action, you can allow traffic to continue flowing while still gaining visibility into potential security risks. This can be useful in situations where blocking the traffic might cause operational disruptions or false positives. However, it's important to note that the monitor action does not actively block traffic, so it's recommended to use it in conjunction with other security measures, such as firewalls, antivirus software, and intrusion prevention systems, to ensure comprehensive protection against cyber threats.
upvoted 8 times
...
chromevandium11
Highly Voted 2 years ago
Selected Answer: CD
I believe the answer should be CD.
upvoted 5 times
...
DavidCA2024
Most Recent 3 months, 1 week ago
Selected Answer: AD
A is correct: Monitor-> allow & log block -> block & log C correct D no. order matters. A Microsoft Windows iSCSi matches first, so not all atacks to windows servers are blocked
upvoted 2 times
...
Malgaw
7 months ago
I don't see how C and D can be true simultaneously. The answer is AD.
upvoted 1 times
...
Mocix
10 months, 1 week ago
A can not be the correct answer because Packet Logging is disabled for the second signature. So, the answers are C and D.
upvoted 1 times
...
ChiaPet75
1 year, 1 month ago
Correct Answer is CD When the IPS engine compares traffic with the signatures in each filter, order matters. The Rules are similar to firewall policy matching; the engine evaluates the filters and signatures at the top of the list first, and applies the first match. The engine skips the subsequent filters. FortiGate Security 7.2 StudyGuide p.392
upvoted 2 times
...
Igor_Mioralli
1 year, 1 month ago
Selected Answer: AD
The Right answer is actually A and D, cause there is a catch - the Fortigate is not blocking ALL attacks to windows server cause it is allowing that iSCSI signature to pass through and the matching traffic is indeed set to log
upvoted 3 times
...
Rian
1 year, 3 months ago
I rathe say it is A&B. because of detail Microsift.windows.iSCSI.target .Dos and Exempt IP's =0
upvoted 1 times
...
Rewrock
1 year, 9 months ago
Selected Answer: CD
I believe the answer should be CD
upvoted 1 times
...
efot
1 year, 11 months ago
Selected Answer: CD
Correct Answer is CD
upvoted 4 times
...
Ney_mediana
2 years ago
I too believe the answer is CD
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago