exam questions

Exam NSE4_FGT-6.2 All Questions

View all questions & answers for the NSE4_FGT-6.2 exam

Exam NSE4_FGT-6.2 topic 1 question 59 discussion

Actual exam question from Fortinet's NSE4_FGT-6.2
Question #: 59
Topic #: 1
[All NSE4_FGT-6.2 Questions]

Refer to the exhibits.


The exhibits show the IPS sensor and DoS policy configuration.
When detecting attacks, which anomaly, signature, or filter will FortiGate evaluate first?

  • A. ip_src_session
  • B. IMAP.Login.Brute.Force
  • C. Location: server Protocol:SMTP
  • D. SMTP.Login.Brute.Force
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hkhan049
Highly Voted 4 years, 3 months ago
I think A is right, because the DoS Policy will be processed before any other policy. https://docs.fortinet.com/document/fortigate/6.2.0/parallel-path-processing-life-of-a-packet/86811/packet-flow-ingress-and-egress-fortigates-without-network-processor-offloading
upvoted 13 times
...
ccsa_ccse
Highly Voted 4 years, 1 month ago
The correct answer is A. DoS scans are handled very early in the life of the packet to determine whether the traffic is valid or is part of a DoS attack.
upvoted 6 times
...
SebaAr22
Most Recent 4 years, 3 months ago
A - ip_src_session is the first
upvoted 3 times
...
Destaire
4 years, 3 months ago
Right answer is B
upvoted 2 times
...
Destaire
4 years, 3 months ago
The answer is B
upvoted 1 times
sogetsu
4 years, 3 months ago
A. “When detecting attacks”, but it doesn't say what kind of attack, so the most possible first to trigger is anomaly, as ip_src_session in the exhibit.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago