nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #44

Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

The correct answer is C. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. D. The sensor will block all attacks aimed at Windows servers. When the IPS engine compares traffic with the signatures in each filter, order matters. The Rules are similar to firewall policy matching; the engine evaluates the filters and signatures at the top of the list first, and applies the first match. The engine skips the subsequent…

Content inspection

Question

Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)

Exhibit

FCP_FGT_AD-7.4 question #44 exhibit

Options

  • AThe sensor will gather a packet log for all matched traffic.
  • BThe sensor will reset all connections that match these signatures.
  • CThe sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature.
  • DThe sensor will block all attacks aimed at Windows servers.

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    11% (5)
  • C
    82% (36)

Explanation

When the IPS engine compares traffic with the signatures in each filter, order matters. The Rules are similar to firewall policy matching; the engine evaluates the filters and signatures at the top of the list first, and applies the first match. The engine skips the subsequent filters.

Topics

#IPS sensor#signature action#intrusion prevention#Windows signatures

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice