ST0-134 · Question #195
A Symantec Endpoint Protection (SEP) administrator creates a firewall policy to block FTP traffic and assigns the policy to all of the SEP clients. The network monitoring team informs the…
The correct answer is D. The server is in the IPS policy excluded hosts list. See the full explanation below for the reasoning.
Question
A Symantec Endpoint Protection (SEP) administrator creates a firewall policy to block FTP traffic and assigns the policy to all of the SEP clients. The network monitoring team informs the administrator that a client system is making an FTP connection to a server. While investigating the problem from the SEP client GUI, the administrator notices that there are zero entries pertaining to FTP traffic in the SEP Traffic log or Packet log. While viewing the Network Activity dialog, there is zero inbound/outbound traffic for the FTP process. What is the most likely reason?
Options
- AThe block rule is below the blue line.
- BThe server has an IPS exception for that traffic.
- CPeer-to-peer authentication is allowing the traffic.
- DThe server is in the IPS policy excluded hosts list.
How the community answered
(49 responses)- A6% (3)
- B4% (2)
- C12% (6)
- D78% (38)
Community Discussion
No community discussion yet for this question.