Intrusion Prevention System - Course-Era Fortinet Fortimanager answers
Which two types of traffic can be offloaded for acceleration
to content processors (CP)? (Choose two.)
IPv6 traffic
SSL VPN
traffic
Intrusion
prevention system (IPS)-inspected traffic
Session helper traffic
Which custom intrusion prevention system (IPS) signature
blocks only FTP passive mode requests?
F-SBID (--attack_id 1002; --name "Block.FTP; --protocol
ftp; --flow from_client; -pattern “PASV”; --no_case;)
F-SBID
(--attack_id 1002; --name "Block.FTP "; --protocol tcp; --service
ftp; --flow from_client; --pattern "PASV"; --no_case;)
F-SBID (--attack_id 1002; --name "Block.PASV.FTP
"; --protocol tcp; --dst_port 20; --flow from_client; --pattern
"PASV"; --no_case;)
F-SBID (--attack_id 1002; --name "Block.PASV.FTP
"; --protocol tcp; --flow from_client; --pattern "PASV";
--no_case;)
config ips global
set nps-accel-mod basic
end
Which two types of traffic will be offloaded to the network
processor (NP)? (Choose two.)
IPsec
phase 2 and hashing
Pre-intrusion
prevention system (IPS) anomaly filtering
SSL encryption and decryption
Antivirus
When creating custom intrusion prevention system (IPS)
signatures, which two options are required? (Choose two.)
--name
--protocol
--severity
–service
Which two scenarios can you block using FortiGuard intrusion
prevention system (IPS) signatures? (Choose two.)
Traffic
with protocol anomalies
Propagation of zero-day malware
Traffic
exploiting known vulnerabilities
Traffic from invalid URLs
Comments