FCP_FGT_AD-7.4 · Question #72
An administrator has configured the following settings: config system settings set ses-denied-traffic enable end config system global set block-session-timer 30 end What are the two results of this…
The correct answer is B. A session for denied traffic is created. C. The number of logs generated by denied traffic is reduced. A session for denied traffic is created. The command set ses-denied-traffic enable ensures that sessions for denied traffic are logged, meaning a session will be created for traffic that is denied by security policies. The number of logs generated by denied traffic is reduced…
Question
An administrator has configured the following settings:
config system settings set ses-denied-traffic enable end config system global set block-session-timer 30 end What are the two results of this configuration? (Choose two.)
Options
- ADenied users are blocked for 30 minutes.
- BA session for denied traffic is created.
- CThe number of logs generated by denied traffic is reduced.
- DDevice detection on all interfaces is enforced for 30 minutes.
How the community answered
(27 responses)- A11% (3)
- B70% (19)
- D19% (5)
Explanation
A session for denied traffic is created. The command set ses-denied-traffic enable ensures that sessions for denied traffic are logged, meaning a session will be created for traffic that is denied by security policies. The number of logs generated by denied traffic is reduced. The set block-session-timer 30 command sets a timer to prevent excessive logging of denied traffic within a short period, which helps reduce the number of logs generated by repeated denied traffic sessions. This timer blocks sessions for a specified period (30 seconds in this case) to avoid overwhelming the log system with repetitive
Topics
Community Discussion
No community discussion yet for this question.