Question 1 of 30
A cybersecurity operations team is tasked with refining the firewall policy for a financial institution\'s critical database cluster. They need to guarantee that authorized administrators from the \"SecOps_Admin\" group can exclusively access this cluster via SSH and HTTPS for maintenance, while all other internal and external traffic attempting to access the cluster on these ports should be explicitly denied. A broad, overarching policy at the bottom of the rulebase denies all traffic to the database cluster that hasn\'t been explicitly permitted by preceding rules. Considering the FortiGate\'s sequential policy evaluation, which placement of the \"SecOps_Admin\" allow rule would most effectively achieve this objective and prevent unintended access or denial?
Position the "SecOps_Admin" allow rule immediately after the default deny-all rule for the database cluster.
Interleave the "SecOps_Admin" allow rule amongst various other specific allow rules for different internal services.
Place the "SecOps_Admin" allow rule at the very top of the entire policy list, before any other rules pertaining to the database cluster.
Integrate the "SecOps_Admin" allow rule within a broader policy that permits all administrative access from any internal subnet.

Preparing for NSE7EFW6.4 Fortinet NSE 7 Enterprise Firewall 6.4? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free