FCSS_EFW_AD-7.4 · Question #48
An administrator applied a block-all IPS profile for client and server targets to secure the server, but the database team reported the application stopped working immediately after. How can an…
The correct answer is A. Use an IPS profile with all signatures in monitor mode and verify patterns before blocking. Applying an aggressive IPS profile without prior testing can disrupt legitimate applications by incorrectly identifying normal traffic as malicious. To prevent disruptions while still monitoring for Enable IPS in "Monitor Mode" first: This allows FortiGate to log and analyze…
Question
An administrator applied a block-all IPS profile for client and server targets to secure the server, but the database team reported the application stopped working immediately after. How can an administrator apply IPS in a way that ensures it does not disrupt existing applications in the network?
Options
- AUse an IPS profile with all signatures in monitor mode and verify patterns before blocking.
- BLimit the IPS profile to server targets only to avoid blocking connections from the server to
- CSelect flow mode in the IPS profile to accurately analyze application patterns.
- DSet the IPS profile signature action to default to discard all possible false positives.
How the community answered
(40 responses)- A75% (30)
- B8% (3)
- C15% (6)
- D3% (1)
Explanation
Applying an aggressive IPS profile without prior testing can disrupt legitimate applications by incorrectly identifying normal traffic as malicious. To prevent disruptions while still monitoring for Enable IPS in "Monitor Mode" first: This allows FortiGate to log and analyze potential threats without actively blocking traffic. Administrators can review logs and fine-tune IPS signatures to minimize false positives before switching to blocking mode. Verify and adjust signature patterns: Some signatures might trigger unnecessary blocks for legitimate application traffic. By analyzing logs, administrators can disable or modify specific rules causing false positives.
Topics
Community Discussion
No community discussion yet for this question.