nerdexam
Fortinet

NSE4 · Question #425

Which statement concerning IPS is false?

The correct answer is D. The status of the last service update attempt from FortiGuard IPS is shown on. The statement claiming that the status of the last FortiGuard IPS service update attempt is explicitly shown on a display element is false, as detailed attempt statuses are typically found in logs rather than a dashboard status field.

Submitted by yaw92· Apr 18, 2026Security Profiles and Content Inspection

Question

Which statement concerning IPS is false?

Options

  • AIPS packages contain an engine and signatures used by both IPS and other flow-based scans.
  • BOne-arm topology with sniffer mode improves performance of IPS blocking.
  • CIPS can detect zero-day attacks.
  • DThe status of the last service update attempt from FortiGuard IPS is shown on

How the community answered

(17 responses)
  • B
    6% (1)
  • D
    94% (16)

Why each option

The statement claiming that the status of the last FortiGuard IPS service update attempt is explicitly shown on a display element is false, as detailed attempt statuses are typically found in logs rather than a dashboard status field.

AIPS packages contain an engine and signatures used by both IPS and other flow-based scans.

IPS packages inherently contain both the detection engine and signatures, which are utilized by IPS and other flow-based inspection features on the FortiGate.

BOne-arm topology with sniffer mode improves performance of IPS blocking.

In an indirect, system-wide sense, using a dedicated FortiGate in sniffer mode for IPS detection can offload processing from an inline device, potentially allowing the inline device to more efficiently handle its blocking functions.

CIPS can detect zero-day attacks.

IPS can detect zero-day attacks by employing behavioral analysis, heuristic scanning, and generic signatures that identify anomalous or malicious patterns, even without a specific signature for a brand-new threat.

DThe status of the last service update attempt from FortiGuard IPS is shown onCorrect

While general FortiGuard IPS update times and subscription status are visible, the granular 'status of the last service update attempt' (e.g., specific success or failure details) is often found in system logs rather than a single, prominent dashboard status field.

Concept tested: FortiGate IPS features and FortiGuard updates

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/523490/intrusion-prevention

Topics

#IPS#Security Profiles#FortiGuard#Updates

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice