Fortinet FortiOS 7.6 NSE4_FGT_AD-7.6 IPS Sensors Exploit Blocking Practice Test

 

This Fortinet NSE4_FGT_AD-7.6 practice test focuses on ips sensors exploit blocking and performance troubleshooting through original applied scenarios aligned to the current Fortinet NSE 4 – FortiOS 7.6 Administrator scope for FortiOS 7.6.0. Use the full ExamSnap NSE4_FGT_AD-7.6 collection for broader practice across all current domains. For broader exam preparation, review the Fortinet NSE4_FGT_AD-7.6 Exam Dumps page.

Question 1

For a FortiGate 7.6 deployment at Datum Corporation, which option correctly addresses the need to block known exploit traffic crossing an allowed firewall policy? The administrator wants a configuration that is easy to audit later.

  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic

Correct answer: A

Explanation

  1. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This directly satisfies the stated requirement.
  2. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  3. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  4. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  5. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.

Learning point: For this FortiOS 7.6 scenario, apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy. IPS sensors evaluate matching traffic against exploit and vulnerability signatures.

Question 2

Southridge Video has validated routing and basic reachability. The remaining requirement is to select signatures relevant to servers rather than enabling every signature indiscriminately. Which action should the team take? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment

Correct answer: D

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  2. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  3. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  4. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This directly satisfies the stated requirement.
  5. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.

Learning point: For this FortiOS 7.6 scenario, use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure. Targeted signature selection improves relevance and can reduce unnecessary inspection load.

Question 3

At Fabrikam Manufacturing, a FortiGate administrator is handling a FortiGate 7.6 change. The requirement is to monitor a suspected exploit signature before enforcing a block in a sensitive environment. What should the administrator do? The team wants the smallest change that directly addresses the requirement.

  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic

Correct answer: D

Explanation

  1. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  2. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  3. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  4. Monitor mode provides evidence without immediately disrupting matching traffic. This directly satisfies the stated requirement.
  5. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.

Learning point: For this FortiOS 7.6 scenario, set the specific IPS signature or filter action to monitor and review events during the validation period. Monitor mode provides evidence without immediately disrupting matching traffic.

Question 4

During a maintenance window at Wingtip Energy, the team must investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy. Which action is the most appropriate? The choice should follow normal FortiOS administration practice.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure

Correct answer: B

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  2. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This directly satisfies the stated requirement.
  3. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  4. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  5. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.

Learning point: For this FortiOS 7.6 scenario, review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection. Broad IPS coverage and decrypted high-volume traffic can increase processing demand.

Question 5

A change review at Lucerne Publishing identifies one requirement: reduce unnecessary IPS work while retaining protection for a known server population. Which FortiGate action best satisfies it? The solution must preserve the existing production design where possible.

  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment

Correct answer: E

Explanation

  1. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  2. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  3. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  4. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  5. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage.

Question 6

While troubleshooting at School of Fine Art, the network operations engineer needs to identify which signature blocked an attack. What is the best next step? The change is being made during a controlled production window.

  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields

Correct answer: E

Explanation

  1. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  2. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  3. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  4. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  5. IPS events identify the signature and enforcement action used on the session. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields. IPS events identify the signature and enforcement action used on the session.

Question 7

Apex Retail is standardizing its FortiGate 7.6 operations. Which approach should it use to inspect exploits delivered inside HTTPS? The team will validate the result immediately after the change.

  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection

Correct answer: B

Explanation

  1. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  2. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This directly satisfies the stated requirement.
  3. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  4. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  5. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.

Learning point: For this FortiOS 7.6 scenario, use full SSL inspection with IPS so the encrypted payload is available to the IPS engine. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS.

Question 8

A production ticket for Proseware Media states that administrators must handle a verified IPS false positive without creating a broad bypass. Which choice is correct? No unrelated security controls should be changed.

  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection

Correct answer: A

Explanation

  1. Specific tuning avoids weakening unrelated IPS protection. This directly satisfies the stated requirement.
  2. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  3. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  4. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  5. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.

Learning point: For this FortiOS 7.6 scenario, create the narrowest exception or per-signature tuning that matches the confirmed benign traffic. Specific tuning avoids weakening unrelated IPS protection.

Question 9

The security team at City Power & Light wants to block known exploit traffic crossing an allowed firewall policy. Which FortiGate configuration or action most directly meets that goal? The administrator wants a configuration that is easy to audit later.

  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment

Correct answer: B

Explanation

  1. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  2. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This directly satisfies the stated requirement.
  3. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  4. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  5. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.

Learning point: For this FortiOS 7.6 scenario, apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy. IPS sensors evaluate matching traffic against exploit and vulnerability signatures.

Question 10

An incident at Margie Travel requires the network operations engineer to select signatures relevant to servers rather than enabling every signature indiscriminately. What should be done first? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure

Correct answer: E

Explanation

  1. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  2. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  3. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  4. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  5. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure. Targeted signature selection improves relevance and can reduce unnecessary inspection load.

Question 11

For a FortiGate 7.6 deployment at Bellows College, which option correctly addresses the need to monitor a suspected exploit signature before enforcing a block in a sensitive environment? The team wants the smallest change that directly addresses the requirement.

  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Set the specific IPS signature or filter action to monitor and review events during the validation period

Correct answer: E

Explanation

  1. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  2. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  3. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  4. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  5. Monitor mode provides evidence without immediately disrupting matching traffic. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, set the specific IPS signature or filter action to monitor and review events during the validation period. Monitor mode provides evidence without immediately disrupting matching traffic.

Question 12

Adventure Works has validated routing and basic reachability. The remaining requirement is to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy. Which action should the team take? The choice should follow normal FortiOS administration practice.

  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy

Correct answer: B

Explanation

  1. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  2. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This directly satisfies the stated requirement.
  3. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  4. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  5. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.

Learning point: For this FortiOS 7.6 scenario, review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection. Broad IPS coverage and decrypted high-volume traffic can increase processing demand.

Question 13

At Fourth Coffee, a FortiGate administrator is handling a FortiGate 7.6 change. The requirement is to reduce unnecessary IPS work while retaining protection for a known server population. What should the administrator do? The solution must preserve the existing production design where possible.

  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields

Correct answer: C

Explanation

  1. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  2. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  3. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This directly satisfies the stated requirement.
  4. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  5. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.

Learning point: For this FortiOS 7.6 scenario, narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage.

Question 14

During a maintenance window at Consolidated Messenger, the team must identify which signature blocked an attack. Which action is the most appropriate? The change is being made during a controlled production window.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Set the specific IPS signature or filter action to monitor and review events during the validation period

Correct answer: B

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  2. IPS events identify the signature and enforcement action used on the session. This directly satisfies the stated requirement.
  3. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  4. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  5. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.

Learning point: For this FortiOS 7.6 scenario, review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields. IPS events identify the signature and enforcement action used on the session.

Question 15

A change review at VanArsdel identifies one requirement: inspect exploits delivered inside HTTPS. Which FortiGate action best satisfies it? The team will validate the result immediately after the change.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic

Correct answer: A

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This directly satisfies the stated requirement.
  2. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  3. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  4. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  5. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.

Learning point: For this FortiOS 7.6 scenario, use full SSL inspection with IPS so the encrypted payload is available to the IPS engine. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS.

Question 16

While troubleshooting at Northwind Health, the network operations engineer needs to handle a verified IPS false positive without creating a broad bypass. What is the best next step? No unrelated security controls should be changed.

  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure

Correct answer: C

Explanation

  1. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  2. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  3. Specific tuning avoids weakening unrelated IPS protection. This directly satisfies the stated requirement.
  4. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  5. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.

Learning point: For this FortiOS 7.6 scenario, create the narrowest exception or per-signature tuning that matches the confirmed benign traffic. Specific tuning avoids weakening unrelated IPS protection.

Question 17

Blue Yonder Airlines is standardizing its FortiGate 7.6 operations. Which approach should it use to block known exploit traffic crossing an allowed firewall policy? The administrator wants a configuration that is easy to audit later.

  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy

Correct answer: E

Explanation

  1. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  2. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  3. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  4. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  5. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy. IPS sensors evaluate matching traffic against exploit and vulnerability signatures.

Question 18

A production ticket for Trey Research states that administrators must select signatures relevant to servers rather than enabling every signature indiscriminately. Which choice is correct? The administrator must choose the action that addresses the stated cause rather than a different FortiGate feature.

  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic

Correct answer: A

Explanation

  1. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This directly satisfies the stated requirement.
  2. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  3. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  4. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.
  5. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to select signatures relevant to servers rather than enabling every signature indiscriminately.

Learning point: For this FortiOS 7.6 scenario, use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure. Targeted signature selection improves relevance and can reduce unnecessary inspection load.

Question 19

The security team at Nod Publishers wants to monitor a suspected exploit signature before enforcing a block in a sensitive environment. Which FortiGate configuration or action most directly meets that goal? The team wants the smallest change that directly addresses the requirement.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure

Correct answer: C

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  2. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  3. Monitor mode provides evidence without immediately disrupting matching traffic. This directly satisfies the stated requirement.
  4. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.
  5. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to monitor a suspected exploit signature before enforcing a block in a sensitive environment.

Learning point: For this FortiOS 7.6 scenario, set the specific IPS signature or filter action to monitor and review events during the validation period. Monitor mode provides evidence without immediately disrupting matching traffic.

Question 20

An incident at Contoso Finance requires the network operations engineer to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy. What should be done first? The choice should follow normal FortiOS administration practice.

  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields

Correct answer: D

Explanation

  1. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  2. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  3. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.
  4. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This directly satisfies the stated requirement.
  5. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to investigate CPU growth after attaching a very broad IPS sensor to a high-throughput policy.

Learning point: For this FortiOS 7.6 scenario, review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection. Broad IPS coverage and decrypted high-volume traffic can increase processing demand.

Question 21

For a FortiGate 7.6 deployment at Litware Logistics, which option correctly addresses the need to reduce unnecessary IPS work while retaining protection for a known server population? The solution must preserve the existing production design where possible.

  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment

Correct answer: E

Explanation

  1. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  2. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  3. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  4. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to reduce unnecessary IPS work while retaining protection for a known server population.
  5. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage.

Question 22

Wide World Importers has validated routing and basic reachability. The remaining requirement is to identify which signature blocked an attack. Which action should the team take? The change is being made during a controlled production window.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic

Correct answer: D

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  2. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  3. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.
  4. IPS events identify the signature and enforcement action used on the session. This directly satisfies the stated requirement.
  5. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to identify which signature blocked an attack.

Learning point: For this FortiOS 7.6 scenario, review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields. IPS events identify the signature and enforcement action used on the session.

Question 23

At Graphic Design Institute, a FortiGate administrator is handling a FortiGate 7.6 change. The requirement is to inspect exploits delivered inside HTTPS. What should the administrator do? The team will validate the result immediately after the change.

  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine

Correct answer: E

Explanation

  1. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  2. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  3. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  4. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to inspect exploits delivered inside HTTPS.
  5. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This directly satisfies the stated requirement.

Learning point: For this FortiOS 7.6 scenario, use full SSL inspection with IPS so the encrypted payload is available to the IPS engine. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS.

Question 24

During a maintenance window at Lamna Healthcare, the team must handle a verified IPS false positive without creating a broad bypass. Which action is the most appropriate? No unrelated security controls should be changed.

  • Set the specific IPS signature or filter action to monitor and review events during the validation period
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Use IPS filters or selected signatures based on protected operating systems, applications, severity, and exposure
  • Review IPS engine utilization, traffic volume, signature scope, SSL inspection load, and sensor filters before disabling protection
  • Review the IPS security-event log and inspect signature, severity, source, destination, action, and policy fields

Correct answer: B

Explanation

  1. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  2. Specific tuning avoids weakening unrelated IPS protection. This directly satisfies the stated requirement.
  3. Targeted signature selection improves relevance and can reduce unnecessary inspection load. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  4. Broad IPS coverage and decrypted high-volume traffic can increase processing demand. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.
  5. IPS events identify the signature and enforcement action used on the session. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to handle a verified IPS false positive without creating a broad bypass.

Learning point: For this FortiOS 7.6 scenario, create the narrowest exception or per-signature tuning that matches the confirmed benign traffic. Specific tuning avoids weakening unrelated IPS protection.

Question 25

A change review at Tailspin Toys identifies one requirement: block known exploit traffic crossing an allowed firewall policy. Which FortiGate action best satisfies it? The administrator wants a configuration that is easy to audit later.

  • Use full SSL inspection with IPS so the encrypted payload is available to the IPS engine
  • Apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy
  • Create the narrowest exception or per-signature tuning that matches the confirmed benign traffic
  • Narrow IPS filters to the relevant platforms, protocols, severities, and vulnerabilities supported by the environment
  • Set the specific IPS signature or filter action to monitor and review events during the validation period

Correct answer: B

Explanation

  1. IPS needs decrypted payload visibility to inspect exploit content carried inside TLS. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  2. IPS sensors evaluate matching traffic against exploit and vulnerability signatures. This directly satisfies the stated requirement.
  3. Specific tuning avoids weakening unrelated IPS protection. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  4. Reducing irrelevant signatures lowers processing and noise while preserving targeted coverage. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.
  5. Monitor mode provides evidence without immediately disrupting matching traffic. This can be appropriate in a different FortiGate situation, but it does not directly satisfy the stated requirement to block known exploit traffic crossing an allowed firewall policy.

Learning point: For this FortiOS 7.6 scenario, apply an IPS sensor with appropriate signatures and blocking actions to the matching firewall policy. IPS sensors evaluate matching traffic against exploit and vulnerability signatures.

Popular posts

img