ExamGecko
Question list
Search
Search

Question 24 - NSE7_NST-7.2 discussion

Report
Export

Refer to the exhibit, which shows a session table entry.

Which statement about FortiGate behavior relating to this session is true?

A.
FortiGate forwarded this session without any inspection.
Answers
A.
FortiGate forwarded this session without any inspection.
B.
FortiGate is performing a security profile inspection using the CPU.
Answers
B.
FortiGate is performing a security profile inspection using the CPU.
C.
FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made.
Answers
C.
FortiGate redirected the client to the captive portal to authenticate, so that a correct policy match could be made.
D.
FortiGate applied only IPS inspection to this session.
Answers
D.
FortiGate applied only IPS inspection to this session.
Suggested answer: B

Explanation:

The session table entry provided shows detailed information about a specific network session passing through the FortiGate device. From the session details, we can see that the session has various attributes such as state, protocol, policy, and inspection details.

The session state (proto_state=11) indicates that the session is being actively processed and inspected.

The npd_state=00000000 suggests that the session is being handled by the CPU rather than offloaded to a Network Processor (NP).

The session is marked for security profile inspection, evident from the detailed byte/packet counts and other session parameters.

From these indicators, it's clear that FortiGate is using its CPU to perform security profile inspection on this session rather than simply forwarding the traffic without inspection or relying solely on IPS inspection.

Fortinet Documentation on Session Table

Fortinet Community Discussion on Session Table

asked 18/09/2024
Najim Abdelmoula
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first