View all questions & answers for the NSE 7 - Enterprise Firewall 7.6 Administrator Exam Materials exam
Question 41 Discussion
Comments
Selected Answers: C
If you encounter a scenario where an IPS signature blocks your native traffic and an application that you are using is considered hostile, you should set the Action to Monitor, at the top of your rules.
A and D are wrong because default action is "Block" for some signatures and "Pass" for other signatures, so there are still potential false-positives
B is wrong because IPS always uses flow-based inspection, so there's no option to select flow mode because it's the only one.
You applied a block-all intrusion prevention system (IPS) profile for client and server targets to secure the server, but the database team reported that applications stopped working immediately after. How can you apply IPS in a way that ensures it does not disrupt existing applications in the network? (Choose one answer)
Brave-Dump Clients Votes