Q: 1
Refer to the exhibit.
As an administrator you have created an IPS profile, but it is not performing as expected. While
testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?
As an administrator you have created an IPS profile, but it is not performing as expected. While
testing you got the output as shown in the exhibit.
What could be the possible reason of the diagnose output shown in the exhibit?Options
Discussion
Makes sense to pick A. If there’s no firewall policy with an IPS profile, the engine runs but can’t inspect traffic, so zero sessions as shown in the output. Pretty sure that matches what happens on FortiGate when IPS isn’t hooked to any active policy. If I’m missing something let me know.
Ugh, gets me every time with these Fortinet semantics. A
Pretty sure it's D since running diagnose test application ipsmonitor 99 could give output like that in certain debug scenarios.
Yeah, it's A for me. The IPS session and VDOM counts at zero usually means no firewall policy has the IPS profile applied, even if the engine's enabled. I've seen similar outputs in production when folks forget to attach the profile to a policy. Pretty sure that's what they're hinting at here, but open to arguments if I missed a detail.
I don’t think it’s D. A is the root cause since without a policy with an IPS profile, you get zero sessions in that diagnose output. Pretty sure that’s what they’re going for here, but correct me if I missed something.
A here, since no firewall policy has the IPS profile attached, so nothing gets inspected. Saw similar logic in practice exams. Slight chance I missed a detail but pretty confident. Official admin guide helps clarify this scenario.
A tbh
C or D, since the output could show up if you run either diagnose test application ipsmonitor 5 or 99. Not sure which exact number was used but these both can dump IPS stats.
I don’t think it’s B. A fits since without a policy using IPS nothing gets triggered.
Hard to say, A, makes sense, since without a firewall policy using the IPS profile, nothing gets inspected. I remember this from similar exam questions and the Fortinet official guide. If someone disagrees let me know, but pretty sure it’s A.
Be respectful. No spam.