NSE4 · Question #179
By default the Intrusion Protection System (IPS) on a FortiGate unit is set to perform which action?
The correct answer is C. Allow all traffic. By default, the Intrusion Protection System (IPS) on a FortiGate unit does not actively block traffic; traffic is allowed until specific IPS profiles and actions are configured and applied to firewall policies.
Question
By default the Intrusion Protection System (IPS) on a FortiGate unit is set to perform which action?
Options
- ABlock all network attacks.
- BBlock the most common network attacks.
- CAllow all traffic.
- DAllow and log all traffic.
How the community answered
(27 responses)- A4% (1)
- C93% (25)
- D4% (1)
Why each option
By default, the Intrusion Protection System (IPS) on a FortiGate unit does not actively block traffic; traffic is allowed until specific IPS profiles and actions are configured and applied to firewall policies.
Blocking all network attacks is an active enforcement action that requires explicit configuration within an IPS profile and application to a firewall policy; it is not the default behavior.
Blocking the most common network attacks also requires specific configuration of IPS signatures and actions, which is not the default state of the IPS upon initial setup.
By default, if an Intrusion Protection System (IPS) profile is not applied to a firewall policy, or if the applied profile's signatures are configured to 'pass' or 'monitor' by default, traffic is allowed to flow through the FortiGate unit without active blocking by the IPS.
While traffic might be allowed, automatically logging all traffic specifically by IPS is part of configuration, and the most fundamental default behavior when IPS is not actively blocking is simply to allow traffic.
Concept tested: FortiGate IPS default action
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/569055/ips-profiles
Topics
Community Discussion
No community discussion yet for this question.