nerdexam
Fortinet

NSE5_FAZ-7.0 · Question #115

Refer to the exhibit. Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by…

The correct answer is A. operation--login & performed_on==BGUI(10.1.1.100)" & userl=admin. On there the task was to create a filter for failed logins from any other location but the local "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."

Log and Data Policy

Question

Refer to the exhibit. Laptopt is used by several administrators to manage FortiAnalyzer. You want to configure a generic text filter that matches all login attempts to the web interface generated by any user other than "admin" and coming from Laptop1:

Which filter will achieve the desired result?

Exhibit

NSE5_FAZ-7.0 question #115 exhibit

Options

  • Aoperation--login & performed_on==BGUI(10.1.1.100)" & userl=admin
  • Boperation--login & srcip=10.1 -1.100 & dstip==10 1.1.210 & user=admin
  • Coperation--login & performed1_on=,'GUI(10.1.1.210)" & user!=admin
  • Doperation--login & dstip=10.1 . 1.2.10 & user1--admin

How the community answered

(55 responses)
  • A
    71% (39)
  • B
    15% (8)
  • C
    9% (5)
  • D
    5% (3)

Explanation

On there the task was to create a filter for failed logins from any other location but the local "Add the text performed_on!~10.0.1.10. This includes any attempts coming from devices with an IP address that is not the one configured on the Local-Client computer."

Topics

#log filter#text filter#web interface login#log search syntax

Community Discussion

No community discussion yet for this question.

Full NSE5_FAZ-7.0 Practice