Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 Application Control Configuration Matching Practice Test

 

This Fortinet NSE4_FGT_AD-7.6 practice test focuses on application control configuration matching and event monitoring through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.

Question 1

The security team at Graphic Design Institute wants to block or monitor recognized applications on allowed traffic. Which FortiGate configuration or action most directly meets that goal? The team will validate the result immediately after the change.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Review application control security-event logs and correlate the event with the traffic session
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: A

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This directly satisfies the stated requirement.
  2. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  3. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  4. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.

Learning point: For this FortiOS 7.6 scenario, create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy. Application control is enforced by a profile attached to the policy handling the session.

Question 2

An incident at Lamna Healthcare requires the SOC analyst to control an application that uses dynamic ports rather than relying only on a service-port object. What should be done first? No unrelated security controls should be changed.

  • Use application signatures or filters in an application control profile
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally

Correct answer: A

Explanation

  1. Application identification can classify traffic based on signatures and behavior rather than only transport port. This directly satisfies the stated requirement.
  2. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  3. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  4. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  5. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.

Learning point: For this FortiOS 7.6 scenario, use application signatures or filters in an application control profile. Application identification can classify traffic based on signatures and behavior rather than only transport port.

Question 3

For a FortiGate 7.6 deployment at Tailspin Toys, which option correctly addresses the need to identify which application signature caused a session to be blocked? The administrator wants a configuration that is easy to audit later.

  • Review application control security-event logs and correlate the event with the traffic session
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Set the relevant application-control action to monitor and review generated events before changing to block

Correct answer: A

Explanation

  1. Application-control logs show the detected application, action, policy, and related session context. This directly satisfies the stated requirement.
  2. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  3. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  4. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  5. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.

Learning point: For this FortiOS 7.6 scenario, review application control security-event logs and correlate the event with the traffic session. Application-control logs show the detected application, action, policy, and related session context.

Question 4

Humongous Insurance has validated routing and basic reachability. The remaining requirement is to measure usage of a risky application before moving from observation to enforcement. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Use application signatures or filters in an application control profile
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use a specific application override or signature action that is more precise than the category-level policy

Correct answer: D

Explanation

  1. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  2. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  3. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  4. Monitoring gathers application visibility without immediately denying the detected traffic. This directly satisfies the stated requirement.
  5. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.

Learning point: For this FortiOS 7.6 scenario, set the relevant application-control action to monitor and review generated events before changing to block. Monitoring gathers application visibility without immediately denying the detected traffic.

Question 5

At Coho Winery, a network administrator is handling a FortiGate 7.6 change. The requirement is to troubleshoot encrypted traffic that remains classified only generically. What should the administrator do? The team wants the smallest change that directly addresses the requirement.

  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Set the relevant application-control action to monitor and review generated events before changing to block

Correct answer: D

Explanation

  1. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  2. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  3. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  4. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This directly satisfies the stated requirement.
  5. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.

Learning point: For this FortiOS 7.6 scenario, use appropriate SSL inspection so application control can obtain the visibility needed for the target application. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient.

Question 6

During a maintenance window at Relecloud, the team must fix an application control profile that exists but is never used. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Set the relevant application-control action to monitor and review generated events before changing to block

Correct answer: B

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  2. A profile has no effect unless the session traverses a policy to which it is applied. This directly satisfies the stated requirement.
  3. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  4. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  5. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.

Learning point: For this FortiOS 7.6 scenario, verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy. A profile has no effect unless the session traverses a policy to which it is applied.

Question 7

A change review at Woodgrove Bank identifies one requirement: allow a broad application category but block one specifically prohibited application. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Review application control security-event logs and correlate the event with the traffic session
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: C

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  2. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  3. Specific signature handling can refine a broader category decision. This directly satisfies the stated requirement.
  4. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.

Learning point: For this FortiOS 7.6 scenario, use a specific application override or signature action that is more precise than the category-level policy. Specific signature handling can refine a broader category decision.

Question 8

While troubleshooting at Alpine Ski House, the SOC analyst needs to reduce false positives after one business application is misidentified. What is the best next step? The change is being made during a controlled production window.

  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Review application control security-event logs and correlate the event with the traffic session

Correct answer: A

Explanation

  1. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This directly satisfies the stated requirement.
  2. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  3. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  4. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  5. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.

Learning point: For this FortiOS 7.6 scenario, validate the signature event and narrowly tune the matching application rule instead of disabling application control globally. Targeted tuning preserves security coverage while addressing the confirmed misclassification.

Question 9

Datum Corporation is standardizing its FortiGate 7.6 operations. Which approach should it use to block or monitor recognized applications on allowed traffic? The team will validate the result immediately after the change.

  • Review application control security-event logs and correlate the event with the traffic session
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy

Correct answer: E

Explanation

  1. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  2. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  3. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  4. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  5. Application control is enforced by a profile attached to the policy handling the session. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy. Application control is enforced by a profile attached to the policy handling the session.

Question 10

A production ticket for Southridge Video states that administrators must control an application that uses dynamic ports rather than relying only on a service-port object. Which choice is correct? No unrelated security controls should be changed.

  • Review application control security-event logs and correlate the event with the traffic session
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use application signatures or filters in an application control profile

Correct answer: E

Explanation

  1. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  2. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  3. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  4. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  5. Application identification can classify traffic based on signatures and behavior rather than only transport port. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use application signatures or filters in an application control profile. Application identification can classify traffic based on signatures and behavior rather than only transport port.

Question 11

The security team at Fabrikam Manufacturing wants to identify which application signature caused a session to be blocked. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.

  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Review application control security-event logs and correlate the event with the traffic session
  • Use application signatures or filters in an application control profile
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: B

Explanation

  1. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  2. Application-control logs show the detected application, action, policy, and related session context. This directly satisfies the stated requirement.
  3. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  4. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.

Learning point: For this FortiOS 7.6 scenario, review application control security-event logs and correlate the event with the traffic session. Application-control logs show the detected application, action, policy, and related session context.

Question 12

An incident at Wingtip Energy requires the SOC analyst to measure usage of a risky application before moving from observation to enforcement. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use a specific application override or signature action that is more precise than the category-level policy
  • Use application signatures or filters in an application control profile
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Set the relevant application-control action to monitor and review generated events before changing to block

Correct answer: E

Explanation

  1. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  2. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  3. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  4. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  5. Monitoring gathers application visibility without immediately denying the detected traffic. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, set the relevant application-control action to monitor and review generated events before changing to block. Monitoring gathers application visibility without immediately denying the detected traffic.

Question 13

For a FortiGate 7.6 deployment at Lucerne Publishing, which option correctly addresses the need to troubleshoot encrypted traffic that remains classified only generically? The team wants the smallest change that directly addresses the requirement.

  • Use a specific application override or signature action that is more precise than the category-level policy
  • Use application signatures or filters in an application control profile
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Review application control security-event logs and correlate the event with the traffic session

Correct answer: D

Explanation

  1. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  2. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  3. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  4. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This directly satisfies the stated requirement.
  5. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.

Learning point: For this FortiOS 7.6 scenario, use appropriate SSL inspection so application control can obtain the visibility needed for the target application. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient.

Question 14

School of Fine Art has validated routing and basic reachability. The remaining requirement is to fix an application control profile that exists but is never used. Which action should the team take? The choice should follow normal FortiOS administration practice.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Use application signatures or filters in an application control profile
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy

Correct answer: E

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  2. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  3. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  4. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  5. A profile has no effect unless the session traverses a policy to which it is applied. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy. A profile has no effect unless the session traverses a policy to which it is applied.

Question 15

At Apex Retail, a network administrator is handling a FortiGate 7.6 change. The requirement is to allow a broad application category but block one specifically prohibited application. What should the administrator do? The solution must preserve the existing production design where possible.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Set the relevant application-control action to monitor and review generated events before changing to block

Correct answer: D

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  2. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  3. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  4. Specific signature handling can refine a broader category decision. This directly satisfies the stated requirement.
  5. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.

Learning point: For this FortiOS 7.6 scenario, use a specific application override or signature action that is more precise than the category-level policy. Specific signature handling can refine a broader category decision.

Question 16

During a maintenance window at Proseware Media, the team must reduce false positives after one business application is misidentified. Which action is the most appropriate? The change is being made during a controlled production window.

  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Use application signatures or filters in an application control profile
  • Review application control security-event logs and correlate the event with the traffic session
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: A

Explanation

  1. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This directly satisfies the stated requirement.
  2. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  3. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  4. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.

Learning point: For this FortiOS 7.6 scenario, validate the signature event and narrowly tune the matching application rule instead of disabling application control globally. Targeted tuning preserves security coverage while addressing the confirmed misclassification.

Question 17

A change review at City Power & Light identifies one requirement: block or monitor recognized applications on allowed traffic. Which FortiGate action best satisfies it? The team will validate the result immediately after the change.

  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Use application signatures or filters in an application control profile
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: B

Explanation

  1. A profile has no effect unless the session traverses a policy to which it is applied. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  2. Application control is enforced by a profile attached to the policy handling the session. This directly satisfies the stated requirement.
  3. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  4. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.

Learning point: For this FortiOS 7.6 scenario, create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy. Application control is enforced by a profile attached to the policy handling the session.

Question 18

While troubleshooting at Margie Travel, the SOC analyst needs to control an application that uses dynamic ports rather than relying only on a service-port object. What is the best next step? No unrelated security controls should be changed.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use application signatures or filters in an application control profile

Correct answer: E

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  2. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  3. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  4. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to control an application that uses dynamic ports rather than relying only on a service-port object.
  5. Application identification can classify traffic based on signatures and behavior rather than only transport port. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use application signatures or filters in an application control profile. Application identification can classify traffic based on signatures and behavior rather than only transport port.

Question 19

Bellows College is standardizing its FortiGate 7.6 operations. Which approach should it use to identify which application signature caused a session to be blocked? The administrator wants a configuration that is easy to audit later.

  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Use application signatures or filters in an application control profile
  • Review application control security-event logs and correlate the event with the traffic session
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Set the relevant application-control action to monitor and review generated events before changing to block

Correct answer: C

Explanation

  1. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  2. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  3. Application-control logs show the detected application, action, policy, and related session context. This directly satisfies the stated requirement.
  4. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.
  5. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which application signature caused a session to be blocked.

Learning point: For this FortiOS 7.6 scenario, review application control security-event logs and correlate the event with the traffic session. Application-control logs show the detected application, action, policy, and related session context.

Question 20

A production ticket for Adventure Works states that administrators must measure usage of a risky application before moving from observation to enforcement. Which choice is correct? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use application signatures or filters in an application control profile
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application
  • Review application control security-event logs and correlate the event with the traffic session
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally

Correct answer: D

Explanation

  1. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  2. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  3. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.
  4. Monitoring gathers application visibility without immediately denying the detected traffic. This directly satisfies the stated requirement.
  5. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to measure usage of a risky application before moving from observation to enforcement.

Learning point: For this FortiOS 7.6 scenario, set the relevant application-control action to monitor and review generated events before changing to block. Monitoring gathers application visibility without immediately denying the detected traffic.

Question 21

The security team at Fourth Coffee wants to troubleshoot encrypted traffic that remains classified only generically. Which FortiGate configuration or action most directly meets that goal? The team wants the smallest change that directly addresses the requirement.

  • Review application control security-event logs and correlate the event with the traffic session
  • Use application signatures or filters in an application control profile
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: E

Explanation

  1. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  2. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  3. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  4. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to troubleshoot encrypted traffic that remains classified only generically.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use appropriate SSL inspection so application control can obtain the visibility needed for the target application. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient.

Question 22

An incident at Consolidated Messenger requires the SOC analyst to fix an application control profile that exists but is never used. What should be done first? The choice should follow normal FortiOS administration practice.

  • Verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy
  • Use application signatures or filters in an application control profile
  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy

Correct answer: A

Explanation

  1. A profile has no effect unless the session traverses a policy to which it is applied. This directly satisfies the stated requirement.
  2. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  3. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  4. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.
  5. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to fix an application control profile that exists but is never used.

Learning point: For this FortiOS 7.6 scenario, verify the intended firewall policy matches the traffic and that the application control profile is enabled on that policy. A profile has no effect unless the session traverses a policy to which it is applied.

Question 23

For a FortiGate 7.6 deployment at VanArsdel, which option correctly addresses the need to allow a broad application category but block one specifically prohibited application? The solution must preserve the existing production design where possible.

  • Set the relevant application-control action to monitor and review generated events before changing to block
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Use application signatures or filters in an application control profile
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally

Correct answer: B

Explanation

  1. Monitoring gathers application visibility without immediately denying the detected traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  2. Specific signature handling can refine a broader category decision. This directly satisfies the stated requirement.
  3. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  4. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.
  5. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to allow a broad application category but block one specifically prohibited application.

Learning point: For this FortiOS 7.6 scenario, use a specific application override or signature action that is more precise than the category-level policy. Specific signature handling can refine a broader category decision.

Question 24

Northwind Health has validated routing and basic reachability. The remaining requirement is to reduce false positives after one business application is misidentified. Which action should the team take? The change is being made during a controlled production window.

  • Use a specific application override or signature action that is more precise than the category-level policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Use application signatures or filters in an application control profile
  • Use appropriate SSL inspection so application control can obtain the visibility needed for the target application

Correct answer: B

Explanation

  1. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  2. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This directly satisfies the stated requirement.
  3. Application control is enforced by a profile attached to the policy handling the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  4. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.
  5. Encrypted payload or handshake information can limit application identification when SSL inspection is insufficient. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce false positives after one business application is misidentified.

Learning point: For this FortiOS 7.6 scenario, validate the signature event and narrowly tune the matching application rule instead of disabling application control globally. Targeted tuning preserves security coverage while addressing the confirmed misclassification.

Question 25

At Blue Yonder Airlines, a network administrator is handling a FortiGate 7.6 change. The requirement is to block or monitor recognized applications on allowed traffic. What should the administrator do? The team will validate the result immediately after the change.

  • Use application signatures or filters in an application control profile
  • Use a specific application override or signature action that is more precise than the category-level policy
  • Review application control security-event logs and correlate the event with the traffic session
  • Create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy
  • Validate the signature event and narrowly tune the matching application rule instead of disabling application control globally

Correct answer: D

Explanation

  1. Application identification can classify traffic based on signatures and behavior rather than only transport port. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  2. Specific signature handling can refine a broader category decision. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  3. Application-control logs show the detected application, action, policy, and related session context. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.
  4. Application control is enforced by a profile attached to the policy handling the session. This directly satisfies the stated requirement.
  5. Targeted tuning preserves security coverage while addressing the confirmed misclassification. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block or monitor recognized applications on allowed traffic.

Learning point: For this FortiOS 7.6 scenario, create an application control profile with the required category, filter, or signature actions and apply it to the matching firewall policy. Application control is enforced by a profile attached to the policy handling the session.

Popular posts

img