nerdexam
Fortinet

NSE4 · Question #50

Review the IPS sensor filter configuration shown in the exhibit Based on the information in the exhibit, which statements are correct regarding the filter? (Choose two.)

The correct answer is C. Its action will block traffic matching these signatures. D. It only takes effect when the sensor is applied to a policy. The IPS sensor filter configuration is set to block traffic matching its signatures, and this filter will only become active when the sensor is applied to an appropriate firewall policy.

Submitted by obi.ng· Apr 18, 2026Security Profiles and Content Inspection

Question

Review the IPS sensor filter configuration shown in the exhibit Based on the information in the exhibit, which statements are correct regarding the filter? (Choose two.)

Exhibit

NSE4 question #50 exhibit

Options

  • AIt does not log attacks targeting Linux servers.
  • BIt matches all traffic to Linux servers.
  • CIts action will block traffic matching these signatures.
  • DIt only takes effect when the sensor is applied to a policy.

How the community answered

(62 responses)
  • A
    5% (3)
  • B
    11% (7)
  • C
    84% (52)

Why each option

The IPS sensor filter configuration is set to block traffic matching its signatures, and this filter will only become active when the sensor is applied to an appropriate firewall policy.

AIt does not log attacks targeting Linux servers.

Without the exhibit, it's impossible to determine if the filter explicitly excludes logging for attacks targeting Linux servers; it might log all detected attacks or have specific logging settings.

BIt matches all traffic to Linux servers.

An IPS filter typically targets specific attack signatures, vulnerabilities, or anomalies, not 'all traffic' to a particular OS type, even if it's configured to detect threats against Linux servers.

CIts action will block traffic matching these signatures.Correct

IPS sensor filters define the action to be taken when traffic matches a configured signature or anomaly; 'block' is a common action to prevent malicious traffic from passing through the FortiGate.

DIt only takes effect when the sensor is applied to a policy.Correct

IPS sensors and their associated filters are not active globally by default; they must be explicitly selected and applied to a firewall policy to inspect and act upon traffic flowing through that policy.

Concept tested: FortiGate IPS sensor filters and policy application

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/603408/configuring-ips-profiles

Topics

#IPS#Security Profiles#Firewall Policies#FortiGate Configuration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice