NSE4 · Question #282
Which of the following features could be used by an administrator to block FTP uploads while still allowing FTP downloads?
The correct answer is B. Data Leak Prevention. Data Leak Prevention (DLP) is the feature that allows an administrator to specifically control and block FTP uploads while permitting downloads, based on policy rules.
Question
Which of the following features could be used by an administrator to block FTP uploads while still allowing FTP downloads?
Options
- AAnti-Virus File-Type Blocking
- BData Leak Prevention
- CNetwork Admission Control
- DFortiClient Check
How the community answered
(29 responses)- B90% (26)
- C7% (2)
- D3% (1)
Why each option
Data Leak Prevention (DLP) is the feature that allows an administrator to specifically control and block FTP uploads while permitting downloads, based on policy rules.
Anti-Virus File-Type Blocking primarily prevents known malicious file types from entering or leaving the network, not for selectively blocking legitimate uploads while allowing downloads.
Data Leak Prevention (DLP) can be configured to inspect FTP traffic and apply granular controls, such as blocking file uploads based on direction, file type, or content signatures while permitting downloads. This allows administrators to prevent sensitive data from leaving the network via FTP.
Network Admission Control (NAC) controls device access to the network based on security posture, not for granular control over application-layer file transfers like FTP uploads/downloads.
FortiClient Check is a component of NAC or endpoint security that verifies FortiClient status, but it does not directly control application-layer protocols like FTP uploads.
Concept tested: Data Leak Prevention (DLP) for granular file transfer control
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526779/data-leak-prevention
Topics
Community Discussion
No community discussion yet for this question.