nerdexam
Fortinet

NSE4 · Question #550

An administrator has configured the following settings: What does the configuration do? (Choose two.)

The correct answer is A. Reduces the amount of logs generated by denied traffic. D. Creates a session for traffic being denied.. This FortiGate configuration reduces the amount of logs generated by denied traffic by creating a session for such traffic, which prevents repeated logging of individual denied packets.

Submitted by anjalisingh· Apr 18, 2026Firewall Policies and Authentication

Question

An administrator has configured the following settings:

What does the configuration do? (Choose two.)

Exhibit

NSE4 question #550 exhibit

Options

  • AReduces the amount of logs generated by denied traffic.
  • BEnforces device detection on all interfaces for 30 minutes.
  • CBlocks denied users for 30 minutes.
  • DCreates a session for traffic being denied.

How the community answered

(35 responses)
  • A
    94% (33)
  • B
    3% (1)
  • C
    3% (1)

Why each option

This FortiGate configuration reduces the amount of logs generated by denied traffic by creating a session for such traffic, which prevents repeated logging of individual denied packets.

AReduces the amount of logs generated by denied traffic.Correct

By enabling the creation of sessions for denied traffic, the FortiGate avoids generating a new log entry for every individual packet that is part of a continuously denied connection, thereby significantly reducing the overall log volume.

BEnforces device detection on all interfaces for 30 minutes.

There is no direct correlation between reducing logs for denied traffic and enforcing device detection on interfaces for a specific duration.

CBlocks denied users for 30 minutes.

While traffic might be denied, creating a session for denied traffic does not inherently block users for a specified duration like a quarantine or ban.

DCreates a session for traffic being denied.Correct

A 'deny session' is a specific FortiGate feature where, instead of dropping individual packets and logging each one separately, a session is created to track denied traffic. This allows the FortiGate to subsequently drop further packets of that same connection silently without generating redundant logs.

Concept tested: FortiGate Deny Session and Logging Reduction

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469902/session-handling

Topics

#Firewall Sessions#Denied Traffic Handling#Logging#Policy Behavior

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice