nerdexam
Fortinet

FCP_FGT_AD-7.6 · Question #81

Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Login.Failed…

The correct answer is B. FortiGate stores a local copy of the packet that matches the signature. When you add a signature to an IPS sensor, the sensor’s override settings take precedence over the default signature action in the FortiGuard database. The IPS profile’s action (Block) overrides the base signature’s action (Pass). The signature “FTP.Login.Failed” is still low…

Submitted by dimitri_ru· Apr 18, 2026Content inspection

Question

Refer to the exhibit. Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit. What can you conclude about the signature when adding the FTP.Login.Failed signature to the IPS Sensor profile?

Exhibit

FCP_FGT_AD-7.6 question #81 exhibit

Options

  • AThe signature setting includes a group of other signatures.
  • BFortiGate stores a local copy of the packet that matches the signature.
  • CFortiGate allows this low severity signature packet and creates a log.
  • DThe signature setting uses a custom rating threshold

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    89% (24)
  • C
    4% (1)

Explanation

When you add a signature to an IPS sensor, the sensor’s override settings take precedence over the default signature action in the FortiGuard database. The IPS profile’s action (Block) overrides the base signature’s action (Pass). The signature “FTP.Login.Failed” is still low severity, but because it’s enabled and logging is on, FortiGate blocks it and logs the event (including packet data)..

Topics

#IPS#Security Profiles#Signature Settings#Packet Logging

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.6 Practice