NSE4 · Question #366
Which traffic can match a firewall policy's "Services" setting? (Choose three.)
The correct answer is A. HTTP C. DNS E. HTTPS. Firewall policies can match traffic based on common application-layer services like HTTP, DNS, and HTTPS, which are defined by specific ports and protocols.
Question
Which traffic can match a firewall policy's "Services" setting? (Choose three.)
Options
- AHTTP
- BSSL
- CDNS
- DRSS
- EHTTPS
How the community answered
(36 responses)- A92% (33)
- B3% (1)
- D6% (2)
Why each option
Firewall policies can match traffic based on common application-layer services like HTTP, DNS, and HTTPS, which are defined by specific ports and protocols.
HTTP (Hypertext Transfer Protocol) traffic, typically using TCP port 80, is a common application-layer service that firewall policies can identify and control.
SSL (Secure Sockets Layer) is a cryptographic protocol that secures communication, operating beneath application protocols like HTTPS, and is not directly a 'service' that a firewall policy matches in the same way as HTTP or DNS.
DNS (Domain Name System) traffic, typically using UDP/TCP port 53, is a fundamental network service that firewall policies can match to manage name resolution queries.
RSS (Really Simple Syndication) is a web feed format for content distribution, which operates over existing network services like HTTP, and is not a network service that a firewall policy directly inspects or matches.
HTTPS (Hypertext Transfer Protocol Secure) traffic, typically using TCP port 443, is an encrypted application-layer service that firewall policies can specify for security and access control.
Concept tested: Firewall policy service matching
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469446/firewall-policy
Topics
Community Discussion
No community discussion yet for this question.