Question 1 of 30
Anya, a network security administrator responsible for a FortiGate firewall protecting a critical infrastructure network, has been alerted by an internal audit that the existing inbound firewall policy for a key business partner is excessively permissive. The current configuration allows a wide range of services and ports, far exceeding the documented operational requirements for the partnership, and presents a significant potential attack vector. Anya is tasked with revising this policy to adhere to the principle of least privilege and to align with current industry best practices for access control, considering the guidance provided by frameworks like the NIST Cybersecurity Framework\'s Access Control (PR.AC) function. What is the most effective and secure methodology Anya should employ to rectify this situation?
Catalog the specific services and ports the partner organization legitimately requires for ongoing operations, create a new, granular FortiGate policy permitting only these identified services and ports, and then systematically disable the previous broad policy.
Analyze recent firewall logs to identify all traffic patterns from the partner organization, then create a new policy that permits traffic matching these observed patterns, and subsequently remove the old policy.
Immediately disable all inbound traffic from the partner organization's IP address range on the FortiGate firewall to eliminate any potential security risk.
Remove all existing inbound rules associated with the partner organization and rely solely on the FortiGate's implicit deny rule to block all traffic from that source.

Preparing for NSE6 Fortinet Network Security Expert 6? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free