nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #125

Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor…

The correct answer is D. Traffic matching the signature will be silently dropped and logged. In an IPS sensor profile, each signature has an assigned action. The exhibit shows FTP.Login.Failed with a 'Block' action. In FortiGate IPS terminology, 'Block' means the matching traffic is silently dropped-no TCP RST or ICMP unreachable is sent to the client-and the event is…

Submitted by marco_it· Apr 18, 2026Content inspection

Question

Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?

Exhibit

FCP_FGT_AD-7.6 question #125 exhibit

Options

  • ATraffic matching the signature will be allowed and logged.
  • BThe signature setting uses a custom rating threshold.
  • CThe signature setting includes a group of other signatures.
  • DTraffic matching the signature will be silently dropped and logged.

How the community answered

(27 responses)
  • A
    4% (1)
  • C
    7% (2)
  • D
    89% (24)

Explanation

In an IPS sensor profile, each signature has an assigned action. The exhibit shows FTP.Login.Failed with a 'Block' action. In FortiGate IPS terminology, 'Block' means the matching traffic is silently dropped-no TCP RST or ICMP unreachable is sent to the client-and the event is logged. This differs from 'Reset' (which sends a TCP RST) and 'Monitor' (which logs but allows traffic). The signature is a single predefined signature, not a group, and it uses the default FortiGuard severity/rating rather than a custom threshold.

Topics

#IPS#Signature-based detection#Security profiles#FortiGate configuration

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice