Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below. When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?
B is correct,
Anomalies can be zero-day or denial of service attack
Are Detected by behaivoral analysis:
Rate Based IPS Signatures
DoS Policies
Protocol Constraint Inspections
Fortigate Security Guide, Page 518
B
Because DoS is disabled
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/486206/dos-protection
Status
The status field is enabled to enable the sensor for the associated anomaly.
C is correct. In FortiOS, the DoS scans precede the policy engine at the incoming interfaces, thus eliminating unnecessary sessions from the firewall process and state table entry during a surge of attack traffic.
https://docs.fortinet.com/document/fortigate/6.0.0/Handbook/48143/intrusion-prevention-system-ips
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
jbernard
Highly Voted 4 years, 10 months agoparidhi
Most Recent 4 years, 3 months agodragonwise
3 years, 8 months agohenzoo
4 years, 4 months agoramzie
4 years, 6 months agoLevis
4 years, 10 months agochameleon_eh
4 years, 10 months agoAril
5 years, 1 month agoxAyx
4 years, 10 months agomontonearm
5 years, 1 month ago