NSE4 · Question #482
Which profile could IPS engine use on an interface that is in sniffer mode? (Choose three)
The correct answer is A. Antivirus (flow based B. Web filtering (PROXY BASED) D. Application Control. When an interface is in sniffer mode, the IPS engine can use flow-based Antivirus, Intrusion Protection, and Application Control profiles to monitor and detect threats from mirrored traffic.
Question
Which profile could IPS engine use on an interface that is in sniffer mode? (Choose three)
Options
- AAntivirus (flow based
- BWeb filtering (PROXY BASED)
- CIntrusion Protection
- DApplication Control
- EEndpoint control
How the community answered
(39 responses)- A74% (29)
- C18% (7)
- E8% (3)
Why each option
When an interface is in sniffer mode, the IPS engine can use flow-based Antivirus, Intrusion Protection, and Application Control profiles to monitor and detect threats from mirrored traffic.
Flow-based Antivirus profiles can inspect traffic as it passes through the FortiGate in sniffer mode, identifying and reporting malware without blocking.
Application Control profiles can identify and report on application usage within the network traffic being sniffed, providing visibility into what applications are running.
Endpoint control typically involves direct communication and management of endpoints, which is an active function not suited for a passive sniffer interface.
Concept tested: FortiGate sniffer mode security profiles
Source: https://docs.fortinet.com/document/fortigate/7.4.0/admin-guide/869094/interface-modes
Topics
Community Discussion
No community discussion yet for this question.