ExamGecko
Question list
Search
Search

Question 146 - NSE4_FGT-7.2 discussion

Report
Export

Refer to the exhibit.

The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.

An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.

What are two solutions for satisfying the requirement? (Choose two.)

A.
Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.
Answers
A.
Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.
B.
Configure a web override rating for download.com and select Malicious Websites as the subcategory.
Answers
B.
Configure a web override rating for download.com and select Malicious Websites as the subcategory.
C.
Set the Freeware and Software Downloads category Action to Warning.
Answers
C.
Set the Freeware and Software Downloads category Action to Warning.
D.
Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
Answers
D.
Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
Suggested answer: B, D

Explanation:

FortiGate Security 7.2 Study Guide (p.268-269): 'If you want to make an exception, for example, rather than unblock access to a potentially unwanted category, change the website to an allowed category. You can also do the reverse. You can block a website that belongs to an allowed category.' 'Static URL filtering is another web filter feature. Configured URLs in the URL filter are checked against the visited websites. If a match is found, the configured action is taken. URL filtering has the same patterns as static domain filtering: simple, regular expressions, and wildcard.'

B) Configure a web override rating for download.com and select Malicious Websites as the subcategory.

This is true because a web override rating is a feature that allows the administrator to change the FortiGuard category of a specific website or domain, and apply a different action to it based on the web filter profile. By configuring a web override rating for download.com and selecting Malicious Websites as the subcategory, the administrator can block access to download.com, which belongs to the Freeware and Software Downloads category by default, without affecting other websites in the same category. The Malicious Websites category has the action Block in the web filter profile shown in the exhibit.

D) Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.

This is true because a static URL filter entry is a feature that allows the administrator to define custom rules for filtering specific URLs or domains, and apply an action to them based on the web filter profile. By configuring a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively, the administrator can block access to download.com and any subdomains or paths under it, without affecting other websites in the Freeware and Software Downloads category. The static URL filter entries have higher priority than the FortiGuard category based filter entries in the web filter profile.

asked 18/09/2024
Victor Gouveia Pennella
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first