A FortiGate administrator receives alerts about a device communicating with a known botnet C2 server. The traffic is encrypted with TLS. Which ATP feature is most effective to block this communication?
Trap 1: Application control to block the C2 application
Application control may not identify the C2 traffic as a specific application.
Trap 2: Antivirus profile with SSL inspection
Antivirus can detect malware but not necessarily block C2 if the traffic is just a beacon.
Trap 3: IPS signature for botnet activity
IPS may detect but requires SSL inspection for encrypted traffic.
- A
Application control to block the C2 application
Why it fails: Application control may not identify the C2 traffic as a specific application.
- B
Antivirus profile with SSL inspection
Why it fails: Antivirus can detect malware but not necessarily block C2 if the traffic is just a beacon.
- C
IPS signature for botnet activity
Why it fails: IPS may detect but requires SSL inspection for encrypted traffic.
- D
DNS Filter with botnet C2 domain blocking
TLS encryption hides the payload, so signature or IPS inspection cannot identify the botnet C2 traffic. DNS Filtering blocks the C2 domain at resolution time, before the TLS session is established, satisfying the requirement to block communication with a known botnet C2 server.