What are the expected actions if traffic matches this IPS sensor?

Examine the IPS sensor configuration shown in the exhibit, and then answer the question-below.

What are the expected actions if traffic matches this IPS sensor? (Choose two.)
A. The sensor will gather a packet log for all matched traffic.
B. The sensor will not block attackers matching the A32S.Botnet signature.
C. The sensor will block all attacks for Windows servers.
D. The sensor will reset all connections that match these signatures.

Download Printable PDF. VALID exam to help you PASS.

10 thoughts on “What are the expected actions if traffic matches this IPS sensor?

  1. B and C are correct – the order of the IPS signatures and Filters matters.

    For details see FortiGate_Security_6.2_Study_Guide-Online.pdf page 528 (IPS Sensor Inspection Sequence)

    1. For sure the packet will be blocked “without logging” if it targets windows. So C is correct and takes out A.
      B is right because the rule is more precise for the A32S.Botnet.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.