Q: 11
What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on
network transmission patterns and application signatures?
Options
Discussion
B. Saw nearly the same question in my exam and B was correct there too.
B. official admin guide and practice labs both highlight application control profiles for signature-based blocking.
Its B. Application control uses the IPS engine for protocol decoders and signatures, not tied to just web traffic like D. Pretty sure that's what the question's getting at, correct me if I'm missing something.
Probably B. Application control uses IPS decoders and can block based on signatures, not just for web traffic.
Probably D since if flow mode is active and you're filtering HTTP, the protocol decoder could work there too.
I've seen similar questions in practice, B is correct.
Its B. Practice tests and Fortinet docs cover how application control uses signatures and protocol decoders for this. Seen similar on exams.
D . If you focus on web traffic, configuring a web filter profile in flow mode can block signatures and patterns using protocol decoders for HTTP(S). I've seen similar points in some of the official Fortinet docs and practice tests. Might be missing something, but that's what makes sense to me right now. Anyone else also use labs to test this scenario?
Had something like this in a mock, and B was right. Application control is what uses those IPS protocol decoders to spot/block app signatures, not just web stuff like D. Pretty sure that's what they're after here, but correct me if you think otherwise.
B vs D - I think B is right here. Application control actually ties into the IPS engine and its decoders, so it can block based on protocol patterns for all kinds of apps, not just web. D is more for web filtering only. Anyone disagree?
Be respectful. No spam.