Zusammenfassung der Ressource
Frage 1
Frage
A known, confirmed attack
Detected when a file or traffic matches a signature pattern:
1- lPS signatures
2- WAF signatures
3- Antivirus signatures
Example: Exploit of known application vulnerabilities
Frage 2
Frage
Can be zero-day or denial of service attacks (DoS)
Detected by behavioral analysis:
1-Rate-based IPS signatures
2-DoS policies
3-Protocol constraints inspection
Example: Abnormally high rate of traffic (DoS/flood)
Frage 3
Frage
Flow-based detection and blocking :
Frage 4
Frage
IPS Components‘ IPS signature databases ‘ Protocol decoders IPS engine (Select 3)
Antworten
-
IPS signature databases
-
Protocol decoders
-
IPS engine
-
IPS Protocol decoders
-
IPS engine databases
Frage 5
Frage
IPS engine (Select 5)
Antworten
-
Application control
-
Anti-virus (flow based)
-
Web filter (flow based)
-
Email filter (flow based)
-
Data Leak Prevention (DLP) (flow based in one-arm sniffer mode)
-
Anti-virus (flow based in one-arm sniffer mode)
-
IPS (flow based)
-
Anti-spam (flow based)
Frage 6
Frage
Decoders parse protocols.
lPS signatures find parts of a protocol that don’t conform.
For example, too many HTTP headers, or a buffer overflow attempt
Unlike proxy-based scans, IPS often does not require IANA standard ports.
Automatically selects decoder for protocol at each OSI layer
Frage 7
Frage
IPS packages are updated by FortiGuard. (Select 3)
Antworten
-
IPS signature databases
-
Protocol decoders
-
IPS engine
-
IPS Protocol
-
IPS databases
-
IPS signature
Frage 8
Frage
Choosing the Signature Database
- [blank_start]Regular[blank_end] : Common attacks with fast, certain identification (default action is block)
- [blank_start]Extended[blank_end] : Performance-intensive
Frage 9
Frage
In fact, because of its size, the extended database is only available for FortiGate models with a smaller disk or RAM. But, for high-security networks, you might be required to enable the extended signatures database.
Frage 10
Frage
Configuring IPS sensors
Frage 11
Frage
IPS Actions (Select 6)
Antworten
-
Pass
-
Monitor
-
Warning
-
Block
-
Reset
-
Default
-
Packet Logging
-
Quarantine
Frage 12
Frage
Which of the following are evaluated first in an lPS sensor?
Antworten
-
A. IPS filter
-
B. IPS signature
Frage 13
Frage
Which IPS component is updated most frequently?