Marcos Avila
Quiz by , created more than 1 year ago

NSE4 6.0 NSE4 6.0 Quiz on App Control, created by Marcos Avila on 17/08/2018.

713
1
0
Marcos Avila
Created by Marcos Avila over 6 years ago
Close

App Control

Question 1 of 16

1

Which statement about the application control database is true?

Select one of the following:

  • a. The application control database is separate from the IPS database.

  • b. The application control database must be updated manually.

Explanation

Question 2 of 16

1

The application control profile consists of three different types of filters: (Select 3)

Select one or more of the following:

  • Categories

  • Application overrides

  • Filter overrides

  • Deny

  • Allow

  • Monitor

Explanation

Question 3 of 16

1

QUIC is a protocol from Google. Instead of using the standard TCP connections for web access it uses UDP which is not scanned by the web filtering. Allowing QUIC instructs FortiGate to inspect Google Chrome packets for a QUIC header and generate logs as a QUIC message. Blocking QUIC forces Google Chrome to use HTTP2/TLS1.2 and FortiGate to log the QUIC as blocked. The default action for QUIC is

Select one of the following:

  • Allow

  • Block.

Explanation

Question 4 of 16

1

Then, FortiGate scans packets for matches, in this order, for the application control profile:

Finally, the application control profile applies the action that you've configured for applications in your selected Categories.

If you have configured any Application Overrides, the application control profile considers those first. it looks for a matching override starting at the top of the list, like firewall policies.

If no matching application override exists, then the application control profile applies the action based on configured Filter Overrides.

Select option below to complete the highlighted text

    3. Categories:
    1. Application Overrides:
    2. Filter Overrides:

Explanation

Question 5 of 16

1

Application control profile actions: (Choose 4)

Select one or more of the following:

  • Allow

  • Monitor

  • Block

  • Quarantine

  • Warning

  • Default

  • Log only

Explanation

Question 6 of 16

1

Which statement about application control is true?

Select one of the following:

  • A. It uses the IPS engine to scan traffic for application patterns.

  • B. It is unable to scan P2P architecture traffic.

Explanation

Question 7 of 16

1

App control three different types of filters

Select one or more of the following:

  • Categories

  • Application overrides

  • Filter overrides

  • Signatures overrides

Explanation

Question 8 of 16

1

Allowing QUIC instructs FortiGate to inspect Google Chrome packets for a QUIC header and generate logs as a QUIC message. *Allow QUIC forces Google Chrome to use HTTP2/TLS1.2 and FortiGate to log the QUIC as blocked. The default action for QUIC is *Allow.

Select one of the following:

  • False

  • True

Explanation

Question 9 of 16

1

Scanning order

Select one of the following:

  • Categories > Application overrides > Filter overrides

  • Application overrides > Categories > Filter overrides

  • Application overrides > Filter overrides > Categories

Explanation

Question 10 of 16

1

Which statement about application control in NGFW policy-based configuration is true?

Select one of the following:

  • A. Applications are applied directly to the firewall policies.

  • B. The application control profile must be applied to firewall policies.

Explanation

Question 11 of 16

1

What statement about the HTTP block page for application control is true?

Select one of the following:

  • A. It can be used only for web applications.

  • B. It works for all types of applications.

Explanation

Question 12 of 16

1

Where do you enable logging of application control events?

Select one of the following:

  • A. Application control logs are enabled in the firewall policy configuration.

  • B. Application control logs are enabled on the Log & Report settings page of FortiGate.

Explanation

Question 13 of 16

1

Which of the following information will not be included in the application event log when using NGFW policy-based mode?

Select one of the following:

  • A. Application control profile name

  • B. Application name

Explanation

Question 14 of 16

1

Force FortiGate to check for new application control updates.

Select one of the following:

  • execute update-now

  • diagnose update-now

  • get execute update-now

Explanation

Question 15 of 16

1

Which TCP port does FortiGuard use for application control?

Select one of the following:

  • A. 53

  • B. 443

Explanation

Question 16 of 16

1

Which SSL/SSH inspection method is recommended for use with application control scanning to improve application detection?

Select one of the following:

  • A. Certificate-based inspection profile

  • B. Deep-inspection profile

Explanation