NSE8_810 · Question #8
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device's Web GUI is accessed. You cannot seem to create a functional custom…
The correct answer is A. Create a very granular firewall policy for that device's IP address which does not perform IPS scanning. D. Change the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection. Explanation/Reference:
Question
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device’s Web GUI is accessed. You cannot seem to create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support. You need to prevent the false positive IPS alerts from occuring. In this scenario, which two actions would accomplish this task? (Choose two.)
Options
- ACreate a very granular firewall policy for that device's IP address which does not perform IPS scanning.
- BReconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
- CCreate a URL filter with the Exempt action for that device's IP address.
- DChange the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.
How the community answered
(32 responses)- A81% (26)
- B6% (2)
- C13% (4)
Explanation
Explanation/Reference:
Topics
Community Discussion
No community discussion yet for this question.