Fortinet
NSE8_810 · Question #8
NSE8_810 Question #8: Real Exam Question with Answer & Explanation
Sign in or unlock NSE8_810 to reveal the answer and full explanation for question #8. The question stem and answer options stay visible for context.
Question
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device's Web GUI is accessed. You cannot seem to create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support. You need to prevent the false positive IPS alerts from occuring. In this scenario, which two actions would accomplish this task? (Choose two.)
Options
- ACreate a very granular firewall policy for that device's IP address which does not perform IPS scanning.
- BReconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
- CCreate a URL filter with the Exempt action for that device's IP address.
- DChange the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.
Unlock NSE8_810 to see the answer
You've previewed enough free NSE8_810 questions. Unlock NSE8_810 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.