Fortinet
NSE4_FGT_AD-7.6 · Question #23
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to…
The correct answer is C. Set the Destination address as Webserver in the Deny policy. You've hit your limit · resets 5am (America/New_York)
Firewall Policies
Question
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration.
An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver.
Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver?
Options
- ADisable match-vip in the Allow_access policy
- BConfigure a One-to-One IP Pool object in a new policy.
- CSet the Destination address as Webserver in the Deny policy.
- DSet the Destination address as Deny_IP in the Allow_access policy.
How the community answered
(32 responses)- A3% (1)
- B16% (5)
- C72% (23)
- D9% (3)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#deny policy#VIP matching#destination address#match-vip
Community Discussion
No community discussion yet for this question.