nerdexam
Fortinet

NSE4_FGT-6.0 · Question #80

Examine the FortiGate configuration: `` config system global set av-failopen pass end ` Examine the output of the following debug command: ` diagnose hardware sysinfo conserve memory conserve mode…

The correct answer is C. It is dropped. See the full explanation below for the reasoning.

Question

Examine the FortiGate configuration:
config system global
 set av-failopen pass
end
Examine the output of the following debug command:
# diagnose hardware sysinfo conserve
memory conserve mode: on
total RAM: 3040 MB
memory used: 2948 MB 97% of total RAM
memory freeable: 92 MB 3% of total RAM
memory used + freeable threshold extreme: 2887 MB 95% of total RAM
memory used threshold red: 2675 MB 88% of total RAM
memory used threshold green: 2492 MB 82% of total RAM
Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection?

Options

  • AIt is allowed, but with no inspection.
  • BIt is allowed with inspection, as long as the inspection is flow based
  • CIt is dropped.
  • DIt is allowed and inspected, as long as the only inspection required is antivirus.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    77% (24)
  • D
    13% (4)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.0 Practice