exam questions

Exam NSE4_FGT-6.0 All Questions

View all questions & answers for the NSE4_FGT-6.0 exam

Exam NSE4_FGT-6.0 topic 1 question 36 discussion

Actual exam question from Fortinet's NSE4_FGT-6.0
Question #: 36
Topic #: 1
[All NSE4_FGT-6.0 Questions]

An administration wants to throttle the total volume of SMTP sessions to their email server. Which of the following DoS sensors can be used to achieve this?

  • A. tcp_port_scan
  • B. ip_dst_session
  • C. udp_flood
  • D. ip_src_session
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Samanosuke
Highly Voted 5 years, 7 months ago
The correct answer is B. The A is only to detect probing.
upvoted 8 times
...
Cyril_the_Squirl
Most Recent 4 years ago
The question says..."To throttle...Volume of SMTP SESSIONS...TO their Server" Answer is B.
upvoted 1 times
...
wassimtrabelsi
4 years, 5 months ago
Answer B is correct : Fortigate Security 6.2 Study Guide page 541
upvoted 1 times
...
Levis
4 years, 10 months ago
Flooding If the number of sessions targeting a single destination in one second is over a threshold, the destination is experiencing flooding. Scan If the number of sessions from a single source in one second is over a threshold, the source is scanning. Source session limit If the number of concurrent sessions from a single source is over a threshold, the source session limit is reached. Destination session limit If the number of concurrent sessions to a single destination is over a threshold, the destination session limit is reached.
upvoted 1 times
...
Fr4nx
4 years, 11 months ago
B. ip_dst_session
upvoted 1 times
...
rjalburq
5 years, 1 month ago
I think D https://kb.fortinet.com/kb/viewContent.do?externalId=FD35259 "If you want to protect your own servers from DoS attacks from the Internet: - Be sure to configure only your own servers as destination of the traffic. You have to use 'Address' objects, not VIPs. - Set the services you provide in your server. This is HTTP, HTTPS, SMTP, etc. - Configure only the anomalies which will match the services of your server(s). For example, if your server provides SMTP access only, use the following anomalies: + tcp_syn_flood, or + tcp_src_session, or + ip_src_session"
upvoted 2 times
Addictioneer
4 years, 9 months ago
Be careful. Continue reading your shared link “If you use (in this case) tcp_dst_session or ip_dst_session, you would be limiting the number of concurrent sessions your server will handle (purpose of Denial of Service).“ If u use “ip_src_session” and let say set the threshold to 100. “Each source IP” will be allowed unless they pass 100 The question asks to protect the volume of traffic to the server. So if we use “ip_dst_session” and set it to 100, the total volume of traffic will be allowed unless it passes the 100 threshold. Perspective! The answer is B
upvoted 3 times
...
...
montonearm
5 years, 1 month ago
i think B
upvoted 2 times
...
[Removed]
5 years, 5 months ago
The Correct answer 100% A If addmin want to all traffic reduce answer b or d. snmp packet l4 so tcp_port_scan is correct check https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Policies/IPv4%20DoS%20Policy.htm https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-firewall-52/Security%20Policies/DoS%20Protection.htm
upvoted 1 times
naicoram
5 years ago
So, based on the second link "DoS Protection", the answer "B ip_dst_session" is the correct ! it said : ip_dst_session : If the number of concurrent IP connections to one destination IP address exceeds the configured threshold value, the action is executed tcp_port_scan : If the SYN packet rate of new TCP connections, including retransmission, from one source IP address exceeds the configured threshold value, the action is executed. for ip_dst_session : " ...connections to one destination IP..." For tcp_port_scan : "... from one source IP address..." So the ip_dst_session is more approriate in this case of "throttle the total volume of SMTP sessions to their email server" !!
upvoted 13 times
...
...
ni
5 years, 5 months ago
Correct answer is C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago