Which of the following is default inspection mode in FortiOS 5.6?
Answer
a. Proxy-based
b. Flow-based with NGFW mode set to profile- based
Question 2
Question
How does NGFW policy-based mode differ from profile-based mode?
Answer
a. Policy-based flow inspection supports web profile overrides.
b. Policy-based flow inspection defines URL filters directly under the firewall policy.
Question 3
Question
Which of the following statements about proxy-based web filtering is true?
Answer
a. Requires more resources than flow-based
b. Transparently analyzes the TCP flow of the traffic
Question 4
Question
Inspection modes
Answer
Flow based
Proxy
Policy based
Route based
Question 5
Question
NGFW mode
Answer
Proxy
Flow-based
Profile-based
Policy-based
Question 6
Question
NGFW mode only applicable to Proxy inspection mode
Answer
True
False
Question 7
Question
Default inspection mode in FortiOS 5.6
Answer
Flow-based
Profile-based
Proxy
Policy-based
Question 8
Question
Requires administrators to create and configure application control and web filtering profiles. then apply them to the selected firewall policy.
Answer
Profile-based
Policy-based
Question 9
Question
Allows administrators to apply application control and web filtering directly to a firewall policy, without having to configure application control and web filtering profiles.
Requires administrators to apply a single SSL/SSH inspection profile to all firewall policies.
Answer
Profile-based
Policy-based
Question 10
Question
Antivirus configuration is always profile-based, regardless of the NGFW mode selection
Default inspection mode in FortiOS 5.6
Uses single-pass direct filter approach (DFA) pattern matching to identify possible attacks or threats
File is scanned on a flow basis as it passes through FortiGate
Requires fewer processing resources
Faster scanning
More thorough inspection
Adds latency
-Complete content is scanned
Two TCP connections
- From client to FortiGate acting as proxy server
-From FortiGate to server
Communication is terminated on Layer 4
More resource intensive
Provides a higher level of threat protection
Answer
Flow-based
Proxy-based
Question 15
Question
Which of the following is default inspection mode in FortiOS 5.6?
Answer
A. Proxy-based.
B. Flow-based with NGFW mode set to profile-based.
Question 16
Question
How does NGFW policy-based mode differ from profile-based mode?
Answer
A. Policy-based flow inspection supports web profile overrides.
B. Policy-based flow inspection defines URL filters directly under the firewall policy.
Question 17
Question
Which of the following statements about proxy-based web filtering is true?
Answer
A. Requires more resources than flow-based
B. Transparently analyzes the TCP flow of the traffic