NSE8_810 · Question #27
Click the Exhibit button. You have deployed several perimeter FortiGates with internal segmentation FortiGates behind them. All FortiGate devices are logging to FortiAnalyzer. When you search the…
The correct answer is A. Apply an application control profile to the perimeter FortiGates that does not inspect DNS traffic to the outbound firewall policy. D. Remove DNS signatures from the IPS profile applied to the outbound firewall policy. Explanation/Reference:
Question
Click the Exhibit button. You have deployed several perimeter FortiGates with internal segmentation FortiGates behind them. All FortiGate devices are logging to FortiAnalyzer. When you search the logs in FortiAnalyzer for denied traffic, you see numerous log messages, as shown in the exhibit, on your perimeter FortiGates only. Which two actions would reduce the number of these log messages? (Choose two.)
Exhibit
Options
- AApply an application control profile to the perimeter FortiGates that does not inspect DNS traffic to the outbound firewall policy.
- BConfigure the internal FortiGates to communicate to FortiGates using port 8888.
- CDisable DNS events logging from FortiGate in the config log fortianalyzer filter section.
- DRemove DNS signatures from the IPS profile applied to the outbound firewall policy.
How the community answered
(20 responses)- A75% (15)
- B10% (2)
- C15% (3)
Explanation
Explanation/Reference:
Topics
Community Discussion
No community discussion yet for this question.
