nerdexam
Fortinet

NSE4_FGT_AD-7.6 · Question #105

Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions are the sensor expected to take? (Choose two.)

The correct answer is C. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. D. The sensor will block all attacks aimed at Windows servers. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. The action for this specific signature is set to Monitor, which means FortiGate will only detect and log the activity but will not block or reset the session. The sensor will block all…

Security Profiles

Question

Refer to the exhibit, which shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions are the sensor expected to take? (Choose two.)

Options

  • AThe sensor will reset all connections that match these signatures.
  • BThe sensor will gather a packet log for all matched traffic.
  • CThe sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature.
  • DThe sensor will block all attacks aimed at Windows servers.

How the community answered

(53 responses)
  • A
    11% (6)
  • B
    25% (13)
  • C
    64% (34)

Explanation

The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. The action for this specific signature is set to Monitor, which means FortiGate will only detect and log the activity but will not block or reset the session. The sensor will block all attacks aimed at Windows servers. The general Windows filter is configured with the Block action, so any traffic matching Windows-related attack signatures will be blocked.

Topics

#IPS sensor#signature actions#packet logging#DoS protection

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT_AD-7.6 Practice