PCNSE · Question #563
Given the screenshot, how did the firewall handle the traffic?
The correct answer is B. Traffic was allowed by policy but denied by profile as a threat. Option B is correct because in next-generation firewalls (like FortiGate), traffic processing has two distinct stages: the firewall policy checks network criteria (source, destination, service) and permits the session, then security profiles (IPS, antivirus, etc.) inspect the…
Question
Given the screenshot, how did the firewall handle the traffic?
Exhibit
Options
- ATraffic was allowed by policy but denied by profile as encrypted.
- BTraffic was allowed by policy but denied by profile as a threat.
- CTraffic was allowed by profile but denied by policy as a threat.
- DTraffic was allowed by policy but denied by profile as a nonstandard port.
How the community answered
(25 responses)- A4% (1)
- B92% (23)
- D4% (1)
Explanation
Option B is correct because in next-generation firewalls (like FortiGate), traffic processing has two distinct stages: the firewall policy checks network criteria (source, destination, service) and permits the session, then security profiles (IPS, antivirus, etc.) inspect the content - in this case, the profile identified a threat within the allowed traffic and blocked it. The log would show "accept" at the policy level alongside a threat/IPS block action at the profile level.
Why the distractors fail:
- A is wrong because encryption-blocked traffic would come from an SSL/deep inspection profile mismatch, not a threat detection - the scenario shows content inspection, not decryption failure.
- C reverses the roles: policies evaluate network attributes (IP, port, interface), not threats - threat detection is exclusively the job of security profiles.
- D is wrong because nonstandard port handling occurs at the policy level (service object matching), not inside a security profile.
Memory tip: Use the phrase "Policy opens the door; Profile searches the bag." If the door opened but the bag check found a weapon, that's exactly option B - policy allowed, profile denied as threat.
Topics
Community Discussion
No community discussion yet for this question.
