Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?
A.
Traffic matching the signature will be allowed and logged.
B.
The signature setting includes a group of other signatures.
C.
Traffic matching the signature will be silently dropped and logged.
D.
The signature setting uses a custom rating threshold.
The correct answer is C, take a look at the 7.2 Security study guide page 394:
Select Block to silently drop traffic matching any of the signatures included in the entry.
So, while the default action would be 'Pass' for this signature the administrator is specifically overriding that to set the Block action. To use the default action the setting would have to be 'Default'.
Answer is C: A bit misleading with the IPS signature set to PASS but the following explanation helps:
When blocking the signature as an 'IPS Signature and Filter' with the action set to 'block', the default IPS signature action is set to 'pass'.
In this case, it will give precedence to the block action of the 'IPS Signature and Filter' and traffic will be blocked, even though the actual IPS signature action is set to 'pass'. https://www.examtopics.com/exams/fortinet/nse4-fgt-7-2/view/13/
C. Traffic matching the signature will be silently dropped and logged.
Reference and download study guide:
https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
rgeneson
Highly Voted 2 years agoRedrum702
Most Recent 1 year agoMengtingLiang
1 year agoGeniusA
1 year, 4 months agoraydel92
1 year, 8 months agoerawemk
1 year, 10 months agoBund
1 year, 11 months agosb_alves
2 years agoalex4988
2 years agosb_alves
2 years ago