FCP_FGT_AD-7.6 · Question #125
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor…
The correct answer is D. Traffic matching the signature will be silently dropped and logged. In an IPS sensor profile, each signature has an assigned action. The exhibit shows FTP.Login.Failed with a 'Block' action. In FortiGate IPS terminology, 'Block' means the matching traffic is silently dropped-no TCP RST or ICMP unreachable is sent to the client-and the event is…
Question
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?
Exhibit
Options
- ATraffic matching the signature will be allowed and logged.
- BThe signature setting uses a custom rating threshold.
- CThe signature setting includes a group of other signatures.
- DTraffic matching the signature will be silently dropped and logged.
How the community answered
(27 responses)- A4% (1)
- C7% (2)
- D89% (24)
Explanation
In an IPS sensor profile, each signature has an assigned action. The exhibit shows FTP.Login.Failed with a 'Block' action. In FortiGate IPS terminology, 'Block' means the matching traffic is silently dropped-no TCP RST or ICMP unreachable is sent to the client-and the event is logged. This differs from 'Reset' (which sends a TCP RST) and 'Monitor' (which logs but allows traffic). The signature is a single predefined signature, not a group, and it uses the default FortiGuard severity/rating rather than a custom threshold.
Topics
Community Discussion
No community discussion yet for this question.
