NSE4 · Question #303
Under what circumstance would you enable LEARN as the Action on a firewall policy?
The correct answer is C. You want to capture data across all traffic and security vectors, and receive learning logs and a. The LEARN action on a firewall policy is used to passively observe network traffic and security events to gather data for policy refinement.
Question
Under what circumstance would you enable LEARN as the Action on a firewall policy?
Options
- AYou want FortiGate to compile security feature activity from various security-related logs, such as
- BYou want FortiGate to monitor a specific security profile in a firewall policy, and provide
- CYou want to capture data across all traffic and security vectors, and receive learning logs and a
- DYou want FortiGate to automatically modify your firewall policies as it learns your networking
How the community answered
(44 responses)- A2% (1)
- B7% (3)
- C86% (38)
- D5% (2)
Why each option
The LEARN action on a firewall policy is used to passively observe network traffic and security events to gather data for policy refinement.
While learning involves compiling security logs, the LEARN action's primary purpose is broader, focusing on capturing all traffic and security vectors for policy refinement, not just compiling existing logs.
Monitoring a specific security profile is a granular aspect that LEARN might contribute data to, but the LEARN action itself provides comprehensive traffic and security insights across the policy.
The LEARN action allows the FortiGate to analyze traffic and security events without enforcing policy, generating learning logs and reports that can be used to refine existing firewall policies or security profiles.
The LEARN action provides data and recommendations but does not automatically modify firewall policies; an administrator must review the findings and manually implement any desired changes.
Concept tested: FortiGate firewall policy LEARN action
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/76807/firewall-policies#action
Topics
Community Discussion
No community discussion yet for this question.