nerdexam
Fortinet

NSE4 · Question #48

Examine the following log message for IPS and identify the valid responses below. (Select all that apply.) 2012-07-01 09:54:28 oid=2 log_id=18433 type=ips subtype=anomaly pri=alert vd=root severity="c

Sign in or unlock NSE4 to reveal the answer and full explanation for question #48. The question stem and answer options stay visible for context.

Submitted by cyberguy42· Apr 18, 2026Logging and Monitoring

Question

Examine the following log message for IPS and identify the valid responses below. (Select all that apply.) 2012-07-01 09:54:28 oid=2 log_id=18433 type=ips subtype=anomaly pri=alert vd=root severity="critical" src="192.168.3.168" dst="192.168.3.170" src_int="port2" serial=0 status="detected" proto=1 service="icmp" count=1 attack_name="icmp_flood" icmp_id="0xa8a4" icmp_type="0x08" icmp_code="0x00" attack_id=16777316 sensor="1" 51 > threshold 50"

Options

  • AThe target is 192.168.3.168.
  • BThe target is 192.168.3.170.
  • CThe attack was detected and blocked.
  • DThe attack was detected only.
  • EThe attack was TCP based.

Unlock NSE4 to see the answer

You've previewed enough free NSE4 questions. Unlock NSE4 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Log analysis#IPS logs#FortiGate logging#Attack identification
Full NSE4 Practice