NSE4_FGT_AD-7.6 · Question #105
Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions are the sensor expected to take? (Choose two.)
The correct answer is C. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. D. The sensor will block all attacks aimed at Windows servers. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. The action for this specific signature is set to Monitor, which means FortiGate will only detect and log the activity but will not block or reset the session. The sensor will block all…
Question
Options
- AThe sensor will reset all connections that match these signatures.
- BThe sensor will gather a packet log for all matched traffic.
- CThe sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature.
- DThe sensor will block all attacks aimed at Windows servers.
How the community answered
(53 responses)- A11% (6)
- B25% (13)
- C64% (34)
Explanation
The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. The action for this specific signature is set to Monitor, which means FortiGate will only detect and log the activity but will not block or reset the session. The sensor will block all attacks aimed at Windows servers. The general Windows filter is configured with the Block action, so any traffic matching Windows-related attack signatures will be blocked.
Topics
Community Discussion
No community discussion yet for this question.