IPS Anomaly Shows 'Pass' Action: Sensor May Not Be Applied
An administrator runs 'diagnose ips anomaly list' and sees many 'tcp_syn_flood' entries. The IPS profile has anomaly detection enabled with action 'pass'. The administrator wants to block such attacks. What change is required?
⚠ Common exam trap
It's easy for candidates to think increasing the threshold (Option A) or enabling flow-based inspection (Option B) will block the attack, when in fact the anomaly action must be explicitly changed from 'pass' to 'block' to enforce dropping of malicious traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the action for the anomaly from 'pass' to 'block'
The 'pass' action in the IPS anomaly detection configuration instructs the FortiGate to only log the detected anomaly without taking any blocking action. Changing the action to 'block' ensures that when the 'tcp_syn_flood' anomaly is detected, the FortiGate will actively drop the offending packets, thereby mitigating the SYN flood attack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the threshold for the anomaly
Why it's wrong here
Adjusting the threshold upward makes the anomaly signature less sensitive, so it requires a higher rate of suspicious traffic before the detection triggers. However, the anomaly's configured action is still 'pass', meaning that even when the threshold is eventually met, the FortiGate will allow the traffic and only log or ignore it. Threshold tuning controls when an anomaly fires, not the consequence of firing, so this does not block the malicious packets.
- ✗
Enable flow-based inspection on the policy
Why it's wrong here
Flow-based inspection and proxy-based inspection are traffic inspection modes that affect how FortiGate processes packets for security features like IPS and application control. IPS anomaly actions are configured independently within the IPS sensor profile; the action of 'pass' or 'block' is honored regardless of whether the policy uses flow-based or proxy-based inspection. Enabling flow-based inspection does not change the anomaly's action and would not cause the FortiGate to drop the anomaly-matching traffic; it only changes the scanning engine's data path and performance characteristics.
- ✗
Add a DoS policy from the same source
Why it's wrong here
A DoS policy in FortiGate is a separate security mechanism designed to counter denial-of-service patterns such as SYN floods or UDP floods, and it works at the policy layer, not inside the IPS sensor. The question explicitly looks to address the IPS anomaly behavior; adding a DoS policy would be an external workaround that does not modify the IPS anomaly's 'pass' action. Even if the DoS policy could block traffic from the source, it would not fix the configuration issue in the IPS profile, and the anomaly would continue to allow traffic when detected.
- ✓
Change the action for the anomaly from 'pass' to 'block'
Why this is correct
The 'block' action for an IPS anomaly instructs the FortiGate's IPS engine to drop packets that match the anomaly signature, thereby preventing the malicious traffic from reaching the destination. Since the current setting is 'pass', the anomaly detection only observes and allows the traffic, which is why the diagnosed anomalies are not being stopped. Setting the action to 'block' is the direct fix, as it changes the response from permitting to actively dropping the offending packets.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.