View all questions & answers for the NSE 7 - Enterprise Firewall 7.6 Administrator Exam Materials exam
Question 2 Discussion
Comments
Selected Answers: B
Selected Answers: A
B is wrong because you would need a webserver hosting a textfile including all the websites you want to block.
Way too much work to just block a few websites
Selected Answers: D
A - extermal conenctor for dynamic ex. IP -- wrong answer
D correct
Selected Answers: B
If the question means blocking these websites within that public IP subnet based on destination public IP address in the packet regardless of Host/SNI/CN, then it should be B (even if it's not needed, and it can be done by simple address group object locally on FortiGate)
C is wrong as application control can't help with filtering domain or IP
D is wrong because we can't create ISDB group locally as ISDBs are created and maintained by FortiGuard
You must update a firewall policy to block multiple websites within the subnet 172.165.58.0/24. What must you do to block these addresses efficiently? (Choose one answer)
Brave-Dump Clients Votes