FCP_FGT_AD-7.6 · Question #81
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Login.Failed…
The correct answer is B. FortiGate stores a local copy of the packet that matches the signature. When you add a signature to an IPS sensor, the sensor’s override settings take precedence over the default signature action in the FortiGuard database. The IPS profile’s action (Block) overrides the base signature’s action (Pass). The signature “FTP.Login.Failed” is still low…
Question
Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Login.Failed signature to the IPS Sensor profile?
Exhibit
Options
- AThe signature setting includes a group of other signatures.
- BFortiGate stores a local copy of the packet that matches the signature.
- CFortiGate allows this low severity signature packet and creates a log.
- DThe signature setting uses a custom rating threshold
How the community answered
(27 responses)- A7% (2)
- B89% (24)
- C4% (1)
Explanation
When you add a signature to an IPS sensor, the sensor’s override settings take precedence over the default signature action in the FortiGuard database. The IPS profile’s action (Block) overrides the base signature’s action (Pass). The signature “FTP.Login.Failed” is still low severity, but because it’s enabled and logging is on, FortiGate blocks it and logs the event (including packet data)..
Topics
Community Discussion
No community discussion yet for this question.
