App Control

Beschreibung

NSE4 6.0 NSE4 6.0 Quiz am App Control, erstellt von Marcos Avila am 17/08/2018.
Marcos Avila
Quiz von Marcos Avila, aktualisiert more than 1 year ago
Marcos Avila
Erstellt von Marcos Avila vor mehr als 6 Jahre
713
1

Zusammenfassung der Ressource

Frage 1

Frage
Which statement about the application control database is true?
Antworten
  • a. The application control database is separate from the IPS database.
  • b. The application control database must be updated manually.

Frage 2

Frage
The application control profile consists of three different types of filters: (Select 3)
Antworten
  • Categories
  • Application overrides
  • Filter overrides
  • Deny
  • Allow
  • Monitor

Frage 3

Frage
QUIC is a protocol from Google. Instead of using the standard TCP connections for web access it uses UDP which is not scanned by the web filtering. Allowing QUIC instructs FortiGate to inspect Google Chrome packets for a QUIC header and generate logs as a QUIC message. Blocking QUIC forces Google Chrome to use HTTP2/TLS1.2 and FortiGate to log the QUIC as blocked. The default action for QUIC is
Antworten
  • Allow
  • Block.

Frage 4

Frage
Then, FortiGate scans packets for matches, in this order, for the application control profile: [blank_start]3. Categories:[blank_end] Finally, the application control profile applies the action that you've configured for applications in your selected Categories. [blank_start]1. Application Overrides:[blank_end] If you have configured any Application Overrides, the application control profile considers those first. it looks for a matching override starting at the top of the list, like firewall policies. [blank_start]2. Filter Overrides:[blank_end] If no matching application override exists, then the application control profile applies the action based on configured Filter Overrides.
Antworten
  • 3. Categories:
  • 1. Application Overrides:
  • 2. Filter Overrides:

Frage 5

Frage
Application control profile actions: (Choose 4)
Antworten
  • Allow
  • Monitor
  • Block
  • Quarantine
  • Warning
  • Default
  • Log only

Frage 6

Frage
Which statement about application control is true?
Antworten
  • A. It uses the IPS engine to scan traffic for application patterns.
  • B. It is unable to scan P2P architecture traffic.

Frage 7

Frage
App control three different types of filters
Antworten
  • Categories
  • Application overrides
  • Filter overrides
  • Signatures overrides

Frage 8

Frage
Allowing QUIC instructs FortiGate to inspect Google Chrome packets for a QUIC header and generate logs as a QUIC message. *Allow QUIC forces Google Chrome to use HTTP2/TLS1.2 and FortiGate to log the QUIC as blocked. The default action for QUIC is *Allow.
Antworten
  • False
  • True

Frage 9

Frage
Scanning order
Antworten
  • Categories > Application overrides > Filter overrides
  • Application overrides > Categories > Filter overrides
  • Application overrides > Filter overrides > Categories

Frage 10

Frage
Which statement about application control in NGFW policy-based configuration is true?
Antworten
  • A. Applications are applied directly to the firewall policies.
  • B. The application control profile must be applied to firewall policies.

Frage 11

Frage
What statement about the HTTP block page for application control is true?
Antworten
  • A. It can be used only for web applications.
  • B. It works for all types of applications.

Frage 12

Frage
Where do you enable logging of application control events?
Antworten
  • A. Application control logs are enabled in the firewall policy configuration.
  • B. Application control logs are enabled on the Log & Report settings page of FortiGate.

Frage 13

Frage
Which of the following information will not be included in the application event log when using NGFW policy-based mode?
Antworten
  • A. Application control profile name
  • B. Application name

Frage 14

Frage
Force FortiGate to check for new application control updates.
Antworten
  • execute update-now
  • diagnose update-now
  • get execute update-now

Frage 15

Frage
Which TCP port does FortiGuard use for application control?
Antworten
  • A. 53
  • B. 443

Frage 16

Frage
Which SSL/SSH inspection method is recommended for use with application control scanning to improve application detection?
Antworten
  • A. Certificate-based inspection profile
  • B. Deep-inspection profile
Zusammenfassung anzeigen Zusammenfassung ausblenden

ähnlicher Inhalt

Urlaub und Reisen
JohannesK
Prüfungsvorbereitung
JohannesK
Teil B, Kapitel 1.3, Handelsregister
Stefan Kurtenbach
Onkologie Grundlagen
angelagiulia
C1 Indirekte Rede
Anna Kania
Financial Accounting
zok42.com
Euro-FH // Zusammenfassung SOPS2
Robert Paul
Österreichische Geschichte ll Mesner (ÖG 2)
Selma Tahirovic
Jour Gesko WS 18/19
Adrienne Tschaudi
Vetie Tierseuchen 2018
Schmolli Schmoll
Vetie Fleisch 2021
Mascha K.