nerdexam
Fortinet

NSE8_810 · Question #8

You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device's Web GUI is accessed. You cannot seem to create a functional custom…

The correct answer is A. Create a very granular firewall policy for that device's IP address which does not perform IPS scanning. D. Change the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection. Explanation/Reference:

FortiGate ZTA

Question

You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device’s Web GUI is accessed. You cannot seem to create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support. You need to prevent the false positive IPS alerts from occuring. In this scenario, which two actions would accomplish this task? (Choose two.)

Options

  • ACreate a very granular firewall policy for that device's IP address which does not perform IPS scanning.
  • BReconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
  • CCreate a URL filter with the Exempt action for that device's IP address.
  • DChange the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.

How the community answered

(32 responses)
  • A
    81% (26)
  • B
    6% (2)
  • C
    13% (4)

Explanation

Explanation/Reference:

Topics

#IPS false positive#SCADA#firewall policy exemption#SSL inspection

Community Discussion

No community discussion yet for this question.

Full NSE8_810 Practice