exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 49 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 49
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibit.
Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit.

What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?

  • A. Traffic matching the signature will be allowed and logged.
  • B. The signature setting includes a group of other signatures.
  • C. Traffic matching the signature will be silently dropped and logged.
  • D. The signature setting uses a custom rating threshold.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rgeneson
Highly Voted 2 years ago
Selected Answer: C
The correct answer is C, take a look at the 7.2 Security study guide page 394: Select Block to silently drop traffic matching any of the signatures included in the entry. So, while the default action would be 'Pass' for this signature the administrator is specifically overriding that to set the Block action. To use the default action the setting would have to be 'Default'.
upvoted 10 times
...
Redrum702
Most Recent 1 year ago
Answer is C: A bit misleading with the IPS signature set to PASS but the following explanation helps: When blocking the signature as an 'IPS Signature and Filter' with the action set to 'block', the default IPS signature action is set to 'pass'. In this case, it will give precedence to the block action of the 'IPS Signature and Filter' and traffic will be blocked, even though the actual IPS signature action is set to 'pass'. https://www.examtopics.com/exams/fortinet/nse4-fgt-7-2/view/13/
upvoted 1 times
...
MengtingLiang
1 year ago
C Select Block to silently drop traffic matching any of the signatures included in the entry.
upvoted 1 times
...
GeniusA
1 year, 4 months ago
C is the correct answer
upvoted 1 times
...
raydel92
1 year, 8 months ago
Selected Answer: C
C. Traffic matching the signature will be silently dropped and logged. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 1 times
...
erawemk
1 year, 10 months ago
Selected Answer: C
Correct answer is C beacause IPS action is set to block, if action is set to default it will allow the traffic.
upvoted 2 times
...
Bund
1 year, 11 months ago
Selected Answer: C
allow but final is block by IPS
upvoted 1 times
...
sb_alves
2 years ago
Selected Answer: C
I didn't understand this application Control link if the theme is IPS... The right answer is C
upvoted 1 times
...
alex4988
2 years ago
Selected Answer: A
Answer A reference http://docs.fortinet.com/document/fortigate/6.0.0/handbook/240599/application-control
upvoted 1 times
sb_alves
2 years ago
I didn't understand this application Control link if the theme is IPS... The right answer is C
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago