FCP_FGT_AD-7.6 · Question #93
An administrator has configured the following settings: What are the two results of this configuration? (Choose two.)
The correct answer is B. A session for denied traffic is created. D. The number of logs generated by denied traffic is reduced. The configuration shown typically includes 'set ses-denied-traffic enable' and 'set block-session-timer <seconds>'. Enabling ses-denied-traffic causes FortiGate to create a session entry even for traffic that is explicitly denied by policy (answer B). Once the session is…
Question
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
Exhibit
Options
- ADenied users are blocked for 30 minutes.
- BA session for denied traffic is created.
- CSession helpers are disabled for denied traffic.
- DThe number of logs generated by denied traffic is reduced.
How the community answered
(24 responses)- A13% (3)
- B83% (20)
- C4% (1)
Explanation
The configuration shown typically includes 'set ses-denied-traffic enable' and 'set block-session-timer <seconds>'. Enabling ses-denied-traffic causes FortiGate to create a session entry even for traffic that is explicitly denied by policy (answer B). Once the session is created and cached, subsequent packets matching the same denied flow are handled by the session table rather than re-evaluated by the policy engine-this means only the first packet generates a deny log entry, significantly reducing the volume of logs for repeated denied flows (answer D). Denied users are not blocked for 30 minutes by this setting, and session helpers are not disabled.
Topics
Community Discussion
No community discussion yet for this question.
