A known, confirmed attack
Detected when a file or traffic matches a signature pattern:
1- lPS signatures
2- WAF signatures
3- Antivirus signatures
Example: Exploit of known application vulnerabilities
Respuesta
Exploit
Anomaly
Pregunta 2
Pregunta
Can be zero-day or denial of service attacks (DoS)
Detected by behavioral analysis:
1-Rate-based IPS signatures
2-DoS policies
3-Protocol constraints inspection
Example: Abnormally high rate of traffic (DoS/flood)
Respuesta
Exploit
Anomaly
Pregunta 3
Pregunta
Flow-based detection and blocking :
Respuesta
Known exploits that match signatures
Network errors and protocol anomalies
Known exploits and protocol anomalies
Network errors that match signatures
Data Leak Prevention (DLP) (flow based in one-arm sniffer mode)
Anti-virus (flow based in one-arm sniffer mode)
IPS (flow based)
Anti-spam (flow based)
Pregunta 6
Pregunta
Decoders parse protocols.
lPS signatures find parts of a protocol that don’t conform.
For example, too many HTTP headers, or a buffer overflow attempt
Unlike proxy-based scans, IPS often does not require IANA standard ports.
Automatically selects decoder for protocol at each OSI layer
Respuesta
What Are Protocol Decoders?
What Are Protocol?
What Are Decoders?
Pregunta 7
Pregunta
IPS packages are updated by FortiGuard. (Select 3)
Respuesta
IPS signature databases
Protocol decoders
IPS engine
IPS Protocol
IPS databases
IPS signature
Pregunta 8
Pregunta
Choosing the Signature Database
- [blank_start]Regular[blank_end] : Common attacks with fast, certain identification (default action is block)
- [blank_start]Extended[blank_end] : Performance-intensive
Respuesta
Regular
Extended
Pregunta 9
Pregunta
In fact, because of its size, the extended database is only available for FortiGate models with a smaller disk or RAM. But, for high-security networks, you might be required to enable the extended signatures database.
Respuesta
True
False
Pregunta 10
Pregunta
Configuring IPS sensors
Respuesta
Two ways:
Add signatures
Add filters
Three ways:
Add signatures
Add filters
Add IPS profile in the policy
Pregunta 11
Pregunta
IPS Actions (Select 6)
Respuesta
Pass
Monitor
Warning
Block
Reset
Default
Packet Logging
Quarantine
Pregunta 12
Pregunta
Which of the following are evaluated first in an lPS sensor?