nerdexam
Fortinet

NSE4_FGT_AD-7.6 · Question #23

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to…

The correct answer is C. Set the Destination address as Webserver in the Deny policy. You've hit your limit · resets 5am (America/New_York)

Firewall Policies

Question

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver?

Options

  • ADisable match-vip in the Allow_access policy
  • BConfigure a One-to-One IP Pool object in a new policy.
  • CSet the Destination address as Webserver in the Deny policy.
  • DSet the Destination address as Deny_IP in the Allow_access policy.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    16% (5)
  • C
    72% (23)
  • D
    9% (3)

Explanation

You've hit your limit · resets 5am (America/New_York)

Topics

#deny policy#VIP matching#destination address#match-vip

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT_AD-7.6 Practice