FCSS_EFW_AD-7.6 · Question #11
What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on network transmission patterns and application signatures?
The correct answer is B. Use application control to limit non-URL-based software handling. FortiGate's IPS protocol decoders analyze network transmission patterns and application signatures to identify and block malicious traffic. Application Control is the feature that allows FortiGate to detect, classify, and block applications based on their behavior and…
Question
What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on network transmission patterns and application signatures?
Options
- AUse the DNS filter to block application signatures and protocol decoders.
- BUse application control to limit non-URL-based software handling.
- CEnable application detection-based SD-WAN rules.
- DConfigure a web filter profile in flow mode.
How the community answered
(25 responses)- A4% (1)
- B72% (18)
- C8% (2)
- D16% (4)
Explanation
FortiGate's IPS protocol decoders analyze network transmission patterns and application signatures to identify and block malicious traffic. Application Control is the feature that allows FortiGate to detect, classify, and block applications based on their behavior and signatures, even when they do not rely on traditional URLs. Application Control works alongside IPS protocol decoders to inspect packet payloads and enforce security policies based on recognized application behaviors. It enables granular control over non-URL-based applications such as P2P traffic, VoIP, messaging apps, and other non- web-based protocols that IPS can identify through protocol decoders. IPS and Application Control together can detect evasive or encrypted applications that might bypass traditional firewall rules.
Topics
Community Discussion
No community discussion yet for this question.