Marcos Avila
Quiz von , erstellt am more than 1 year ago

NSE4 6.0 NSE4 6.0 Quiz am App Control, erstellt von Marcos Avila am 17/08/2018.

701
1
0
Marcos Avila
Erstellt von Marcos Avila vor fast 6 Jahre
Schließen

App Control

Frage 1 von 16

1

Which statement about the application control database is true?

Wähle eine der folgenden:

  • a. The application control database is separate from the IPS database.

  • b. The application control database must be updated manually.

Erklärung

Frage 2 von 16

1

The application control profile consists of three different types of filters: (Select 3)

Wähle eine oder mehr der folgenden:

  • Categories

  • Application overrides

  • Filter overrides

  • Deny

  • Allow

  • Monitor

Erklärung

Frage 3 von 16

1

QUIC is a protocol from Google. Instead of using the standard TCP connections for web access it uses UDP which is not scanned by the web filtering. Allowing QUIC instructs FortiGate to inspect Google Chrome packets for a QUIC header and generate logs as a QUIC message. Blocking QUIC forces Google Chrome to use HTTP2/TLS1.2 and FortiGate to log the QUIC as blocked. The default action for QUIC is

Wähle eine der folgenden:

  • Allow

  • Block.

Erklärung

Frage 4 von 16

1

Then, FortiGate scans packets for matches, in this order, for the application control profile:

Finally, the application control profile applies the action that you've configured for applications in your selected Categories.

If you have configured any Application Overrides, the application control profile considers those first. it looks for a matching override starting at the top of the list, like firewall policies.

If no matching application override exists, then the application control profile applies the action based on configured Filter Overrides.

Klicke und ziehe, um den Text zu vervollständigen.

    3. Categories:
    1. Application Overrides:
    2. Filter Overrides:

Erklärung

Frage 5 von 16

1

Application control profile actions: (Choose 4)

Wähle eine oder mehr der folgenden:

  • Allow

  • Monitor

  • Block

  • Quarantine

  • Warning

  • Default

  • Log only

Erklärung

Frage 6 von 16

1

Which statement about application control is true?

Wähle eine der folgenden:

  • A. It uses the IPS engine to scan traffic for application patterns.

  • B. It is unable to scan P2P architecture traffic.

Erklärung

Frage 7 von 16

1

App control three different types of filters

Wähle eine oder mehr der folgenden:

  • Categories

  • Application overrides

  • Filter overrides

  • Signatures overrides

Erklärung

Frage 8 von 16

1

Allowing QUIC instructs FortiGate to inspect Google Chrome packets for a QUIC header and generate logs as a QUIC message. *Allow QUIC forces Google Chrome to use HTTP2/TLS1.2 and FortiGate to log the QUIC as blocked. The default action for QUIC is *Allow.

Wähle eine der folgenden:

  • False

  • True

Erklärung

Frage 9 von 16

1

Scanning order

Wähle eine der folgenden:

  • Categories > Application overrides > Filter overrides

  • Application overrides > Categories > Filter overrides

  • Application overrides > Filter overrides > Categories

Erklärung

Frage 10 von 16

1

Which statement about application control in NGFW policy-based configuration is true?

Wähle eine der folgenden:

  • A. Applications are applied directly to the firewall policies.

  • B. The application control profile must be applied to firewall policies.

Erklärung

Frage 11 von 16

1

What statement about the HTTP block page for application control is true?

Wähle eine der folgenden:

  • A. It can be used only for web applications.

  • B. It works for all types of applications.

Erklärung

Frage 12 von 16

1

Where do you enable logging of application control events?

Wähle eine der folgenden:

  • A. Application control logs are enabled in the firewall policy configuration.

  • B. Application control logs are enabled on the Log & Report settings page of FortiGate.

Erklärung

Frage 13 von 16

1

Which of the following information will not be included in the application event log when using NGFW policy-based mode?

Wähle eine der folgenden:

  • A. Application control profile name

  • B. Application name

Erklärung

Frage 14 von 16

1

Force FortiGate to check for new application control updates.

Wähle eine der folgenden:

  • execute update-now

  • diagnose update-now

  • get execute update-now

Erklärung

Frage 15 von 16

1

Which TCP port does FortiGuard use for application control?

Wähle eine der folgenden:

  • A. 53

  • B. 443

Erklärung

Frage 16 von 16

1

Which SSL/SSH inspection method is recommended for use with application control scanning to improve application detection?

Wähle eine der folgenden:

  • A. Certificate-based inspection profile

  • B. Deep-inspection profile

Erklärung