exam questions

Exam NSE4_FGT-6.4 All Questions

View all questions & answers for the NSE4_FGT-6.4 exam

Exam NSE4_FGT-6.4 topic 1 question 38 discussion

Actual exam question from Fortinet's NSE4_FGT-6.4
Question #: 38
Topic #: 1
[All NSE4_FGT-6.4 Questions]

Refer to the exhibit.

Based on the raw log, which two statements are correct? (Choose two.)

  • A. Traffic is blocked because Action is set to DENY in the firewall policy.
  • B. Traffic belongs to the root VDOM.
  • C. This is a security log.
  • D. Log severity is set to error on FortiGate.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Djohan23
Highly Voted 4 years ago
as you can see the parameter on the log view, 1. "vd=root" which means vdom is root. 2. "type=utm" which means security log event. So, B & C is the correct answer.
upvoted 21 times
...
Melvin91
Most Recent 2 years, 6 months ago
Why A is wrong? Can anyone explain ?
upvoted 1 times
ariel_df
2 years, 5 months ago
Do you know why A is wrong?
upvoted 1 times
...
...
ChuckC
2 years, 9 months ago
Selected Answer: BC
FortiGate_Security_7.0_Study page 268 and 270
upvoted 2 times
...
juanK1982
3 years ago
Selected Answer: BC
B & C is the correct answer
upvoted 1 times
...
SandroAlex
3 years, 1 month ago
Selected Answer: BC
B e C são verdadeiras
upvoted 1 times
...
mario156090
3 years, 2 months ago
Selected Answer: BC
B+C is the answer.
upvoted 1 times
...
forti_Ctes
3 years, 7 months ago
I think B and C
upvoted 3 times
...
franger
3 years, 8 months ago
B and C are correct: if you pay attention to the security log web filter you can enable the UTM log but if you set the firewall policy as accepting the logs will continue to be blocked which means the answer A is not correct: https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/986892/sample-logs-by-log-type (almost in the middle you'll see web filter logs).
upvoted 2 times
...
FortiSherlock
3 years, 9 months ago
I was confused by this question as well. I thought A, B and C would all be obviously correct. action is blocked, vd is root and type is utm according to the log. The tricky part is the last part of answer A, though. :-) The action in the firewall policy cannot be set to "DENY" because subtype here is "webfilter" and a webfilter does not have an action "DENY", is only has the action "BLOCK".
upvoted 3 times
2021gene
3 years, 8 months ago
Perhaps Im wrong, but If you are working in policy based mode(not profile), you apply the category directly on the policy, and the only actions, are accept or deny. See FortiGate_Security_6.4_Study page 375...besides this there is part in the log where it says profile=default...that makes me think that the working mode is profile based instead of policy based, in such case I agree with you, the answer should be B, C
upvoted 2 times
...
...
wamendoza
3 years, 9 months ago
I think it's A and B if you see the log it clearly says action = blocked and the message (msg) says "URL belongs to a denied category in a policy". I did the practice and when I put blocked in the action in category it returns the same log. Also, are we sure that UTM is a security log? You can do the practice by going to web filter, blocking some category and trying to enter. Then you must execute in the CLI "execute log filter category 3 " and "execute log display" you will see the same message in the log
upvoted 1 times
...
Bluegrass168
3 years, 11 months ago
UTM and Root are shown on the log. So - B and C are right!
upvoted 1 times
...
davidone
4 years ago
I think B and C.
upvoted 3 times
...
FeNadege
4 years, 1 month ago
B and C are Correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago