nerdexam
Fortinet

FCP_FMG_AD-7.6 · Question #28

Refer to the exhibits. FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An…

The correct answer is B. FortiManager and FortiGate have different IPS database versions. When FortiGate devices download IPS signatures from FortiManager acting as a local FortiGuard Distribution Server, both the FortiGate and FortiManager need to have synchronized IPS database versions to ensure compatibility. If FortiManager and FortiGate have different IPS…

FortiGuard and Fabric Connectors

Question

Refer to the exhibits. FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ- NGFW-1 However, FortiGate does not recognize the new IPS signature from FortiManager. What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?

Exhibits

FCP_FMG_AD-7.6 question #28 exhibit 1
FCP_FMG_AD-7.6 question #28 exhibit 2
FCP_FMG_AD-7.6 question #28 exhibit 3

Options

  • AFortiGate must enable rating for the FortiManager IP address, 192.168.1.120, in server list 1.
  • BFortiManager and FortiGate have different IPS database versions.
  • CThe administrator must enable IPv6 connections for FortiGuard services on FortiManager.
  • DThe administrator must enable the fortiguard-anycast option to correctly download all signatures

How the community answered

(41 responses)
  • A
    10% (4)
  • B
    71% (29)
  • C
    15% (6)
  • D
    5% (2)

Explanation

When FortiGate devices download IPS signatures from FortiManager acting as a local FortiGuard Distribution Server, both the FortiGate and FortiManager need to have synchronized IPS database versions to ensure compatibility. If FortiManager and FortiGate have different IPS database versions, the FortiGate will not recognize new or updated IPS signatures that were pushed from FortiManager.

Topics

#FortiGuard FDS#IPS signatures#database version mismatch#closed network

Community Discussion

No community discussion yet for this question.

Full FCP_FMG_AD-7.6 Practice