Examine the IPS sensor and DoS policy configuration shown in the exhibit, then answer the question below. When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?
B is correct,
Anomalies can be zero-day or denial of service attack
Are Detected by behaivoral analysis:
Rate Based IPS Signatures
DoS Policies
Protocol Constraint Inspections
Fortigate Security Guide, Page 518
B
Because DoS is disabled
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/486206/dos-protection
Status
The status field is enabled to enable the sensor for the associated anomaly.
C is correct. In FortiOS, the DoS scans precede the policy engine at the incoming interfaces, thus eliminating unnecessary sessions from the firewall process and state table entry during a surge of attack traffic.
https://docs.fortinet.com/document/fortigate/6.0.0/Handbook/48143/intrusion-prevention-system-ips
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
jbernard
Highly Voted 5 years agoparidhi
Most Recent 4 years, 5 months agodragonwise
3 years, 10 months agohenzoo
4 years, 6 months agoramzie
4 years, 8 months agoLevis
5 years agochameleon_eh
5 years agoAril
5 years, 3 months agoxAyx
5 years agomontonearm
5 years, 3 months ago