NSE4 · Question #411
Which of the following actions that can be taken by the Data Leak Prevention scanning? (Choose three.)
The correct answer is A. Block D. Log only E. Quarantine IP address. Data Leak Prevention (DLP) scanning on FortiGate supports actions such as blocking the data transmission, quarantining the source IP address, or simply logging the detected event.
Question
Which of the following actions that can be taken by the Data Leak Prevention scanning? (Choose three.)
Options
- ABlock
- BReject
- CTag
- DLog only
- EQuarantine IP address
How the community answered
(68 responses)- A88% (60)
- B9% (6)
- C3% (2)
Why each option
Data Leak Prevention (DLP) scanning on FortiGate supports actions such as blocking the data transmission, quarantining the source IP address, or simply logging the detected event.
FortiGate DLP can be configured to block the transmission of files or content that matches a defined DLP sensor, preventing data exfiltration.
'Reject' is not a standard, distinct action available in FortiGate DLP policies; 'Block' is the common enforcement action.
'Tag' is not a direct enforcement action in FortiGate DLP policies but rather a classification or labeling mechanism used in broader data management solutions.
A DLP policy can be set to 'Log only', which means it will record an event when sensitive data is detected but will not take any enforcement action.
FortiGate DLP offers the action to 'Quarantine IP address', which isolates the source IP address involved in a data leak incident for a specified duration.
Concept tested: FortiGate DLP policy actions
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/526786/data-leak-prevention
Topics
Community Discussion
No community discussion yet for this question.