Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam FCSS_SASE_AD-23 Topic 1 Question 10 Discussion

Actual exam question for Fortinet's FCSS_SASE_AD-23 exam
Question #: 10
Topic #: 1
[All FCSS_SASE_AD-23 Questions]

An organization wants to block all video and audio application traffic but grant access to videos from CNN Which application override action must you configure in the Application Control with Inline-CASB?

Show Suggested Answer Hide Answer
Suggested Answer: D

To block all video and audio application traffic while granting access to videos from CNN, you need to configure an application override action in the Application Control with Inline-CASB. Here is the step-by-step detailed explanation:

Application Control Configuration:

Application Control is used to identify and manage application traffic based on predefined or custom application signatures.

Inline-CASB (Cloud Access Security Broker) extends these capabilities by allowing more granular control over cloud applications.

Blocking Video and Audio Applications:

To block all video and audio application traffic, you can create a policy within Application Control to deny all categories related to video and audio streaming.

Granting Access to Specific Videos (CNN):

To allow access to videos from CNN specifically, you must create an override rule within the same Application Control profile.

The override action 'Exempt' ensures that traffic to specified URLs (such as those from CNN) is not subjected to the blocking rules set for other video and audio traffic.

Configuration Steps:

Navigate to the Application Control profile in the FortiSASE interface.

Set the application categories related to video and audio streaming to 'Block.'

Add a new override entry for CNN video traffic and set the action to 'Exempt.'


FortiOS 7.2 Administration Guide: Detailed steps on configuring Application Control and Inline-CASB.

Fortinet Training Institute: Provides scenarios and examples of using Application Control with Inline-CASB for specific use cases.

Contribute your Thoughts:

Viva
2 months ago
Exempt, the obvious choice. Unless you want everyone to start watching cat videos instead of CNN. Then you'd really be in trouble!
upvoted 0 times
...
Lenny
2 months ago
Allow? Pfft, that defeats the whole purpose. Exempt is the way to go, no doubt about it.
upvoted 0 times
...
Lawrence
3 months ago
Permit? Sounds like a half-measure to me. Gotta go with Exempt to really get the job done.
upvoted 0 times
Maddie
1 months ago
Exempt is definitely the most secure choice for this situation, it ensures only CNN videos are accessible.
upvoted 0 times
...
Stephanie
2 months ago
I think Permit might still allow some unwanted traffic, Exempt seems like the safer option.
upvoted 0 times
...
Lorean
2 months ago
I agree, Exempt is the way to go for blocking all video and audio except for CNN.
upvoted 0 times
...
...
Martha
3 months ago
That makes sense too. It's important to consider the specific requirements of the organization.
upvoted 0 times
...
Noe
3 months ago
I disagree, I believe the answer is A) Allow because we want to block all video and audio applications except for CNN videos.
upvoted 0 times
...
Kathrine
3 months ago
Pass? Nah, that's too sneaky. Gotta be more upfront about it. Exempt for the win!
upvoted 0 times
...
Rosio
3 months ago
Hmm, I'd say Exempt. Gotta let the people get their CNN fix, you know?
upvoted 0 times
Laurel
2 months ago
I agree, Pass seems like the right choice here.
upvoted 0 times
...
Nickie
3 months ago
I think Pass would be a better option.
upvoted 0 times
...
Jerilyn
3 months ago
Exempt
upvoted 0 times
...
...
Martha
3 months ago
I think the answer is D) Exempt because we want to grant access to videos from CNN.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77