Fortinet
NSE8_812 · Question #87
A customer has a SCADA environmental control device that is triggering a false-positive IPS alert whenever the Web GUI of the device is accessed. You cannot create a functional custom IPS filter to…
The correct answer is A. Create a URL filter with the Exempt action for that device IP address. Correct answers are A and C.
Advanced Threat Protection and Content Inspection
Question
A customer has a SCADA environmental control device that is triggering a false-positive IPS alert whenever the Web GUI of the device is accessed. You cannot create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support. You need to prevent the false positive IPS alerts from occurring. In this scenario, which two actions will accomplish this task? (Choose two.)
Options
- ACreate a URL filter with the Exempt action for that device IP address.
- BChange the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.
- CCreate a very specific firewall policy for that device IP address which does not perform IPS scanning.
- DReconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
How the community answered
(19 responses)- A79% (15)
- B5% (1)
- C11% (2)
- D5% (1)
Explanation
Correct answers are A and C.
Topics
#IPS false positive#SCADA#firewall policy exemption#SSL inspection
Community Discussion
No community discussion yet for this question.