TEST CERT

Descrição

Test de Certificación
sebastianzo
Quiz por sebastianzo, atualizado more than 1 year ago
sebastianzo
Criado por sebastianzo mais de 9 anos atrás
2905
9

Resumo de Recurso

Questão 1

Questão
For FortiGate devices equipped with Network Processor (NP) chips, which are true? (Choose three.)
Responda
  • For each new IP session, the first packet always goes to the CPU.
  • The kernel does not need to program the NPU. When the NPU sees the traffic, it determines by itself whether it can process the traffic.
  • Once offloaded, unless there are errors, the NP forwards all subsequent packets. The CPU does not process them.
  • When the last packet is sent or received, such as a TCP FIN or TCP RST signal, the NP returns this session to the CPU for tear down.
  • Sessions for policies that have a security profile enabled can be NP offloaded.

Questão 2

Questão
In "diag debug flow" output, you see the message “Allowed by Policy-1: SNAT”. Which is true?
Responda
  • The packet matched the topmost policy in the list of firewall policies.
  • The packet matched the firewall policy whose policy ID is 1.
  • The packet matched a firewall policy which allows the packet and skips UTM checks.
  • The policy allowed the packet and applied session NAT.

Questão 3

Questão
Which is NOT true about the settings for an IP pool type port block allocation?
Responda
  • A Block Size defines the number of connections.
  • Blocks Per User defines the number of connection blocks for each user.
  • An Internal IP Range defines the IP addresses permitted to use the pool.
  • An External IP Range defines the IP addresses in the pool.

Questão 4

Questão
If you enable the option "Generate Logs when Session Starts", what effect does this have on the number of traffic log messages generated for each session?
Responda
  • No traffic log message is generated.
  • One traffic log message is generated.
  • Two traffic log messages are generated.
  • A log message is only generated if there is a security event.

Questão 5

Questão
Which traffic can match a firewall policy's "Services" setting? (Choose three.)
Responda
  • HTTP
  • SSL
  • DNS
  • RSS
  • HTTPS

Questão 6

Questão
Which correctly define "Section View" and "Global View" for firewall policies? (Choose two.)
Responda
  • Section View lists firewall policies primarily by their interface pairs.
  • Section View lists firewall policies primarily by their sequence number.
  • Global View lists firewall policies primarily by their interface pairs.
  • Global View lists firewall policies primarily by their policy sequence number.
  • The 'any' interface may be used with Section View.

Questão 7

Questão
Which is true of FortiGate's session table?
Responda
  • NAT/PAT is shown in the central NAT table, not the session table.
  • It shows TCP connection states.
  • It shows IP, SSL, and HTTP sessions.
  • It does not show UDP or ICMP connection state codes, because those protocols are connectionless.

Questão 8

Questão
Which is true about incoming and outgoing interfaces in firewall policies?
Responda
  • A physical interface may not be used.
  • A zone may not be used.
  • Multiple interfaces may not be used for both incoming and outgoing.
  • Source and destination interfaces are mandatory.

Questão 9

Questão
Which is NOT true about source matching with firewall policies?
Responda
  • A source address object must be selected in the firewall policy.
  • A source user/group may be selected in the firewall policy.
  • A source device may be defined in the firewall policy.
  • A source interface must be selected in the firewall policy.
  • A source user/group and device must be specified in the firewall policy.

Questão 10

Questão
Which define device identification? (Choose two.)
Responda
  • Device identification is enabled by default on all interfaces.
  • Enabling a source device in a firewall policy enables device identification on the source interfaces of that policy.
  • You cannot combine source user and source device in the same firewall policy.
  • FortiClient can be used as an agent based device identification technique.
  • Only agentless device identification techniques are supported.

Questão 11

Questão
Which are valid replies from a RADIUS server to an ACCESS-REQUEST packet from a FortiGate? (Choose two.)
Responda
  • ACCESS-CHALLENGE
  • ACCESS-RESTRICT
  • ACCESS-PENDING
  • ACCESS-REJECT

Questão 12

Questão
Which methods can FortiGate use to send a One Time Password (OTP) to Two-Factor Authentication users? (Choose three.)
Responda
  • Hardware FortiToken
  • Web Portal
  • Email
  • USB Token
  • Software FortiToken (FortiToken mobile)

Questão 13

Questão
Which best describes the authentication timeout?
Responda
  • How long FortiGate waits for the user to enter his or her credentials.
  • How long a user is allowed to send and receive traffic before he or she must authenticate again.
  • How long an authenticated user can be idle (without sending traffic) before they must authenticate again.
  • How long a user-authenticated session can exist without having to authenticate again.

Questão 14

Questão
Which authentication methods does FortiGate support for firewall authentication? (Choose two.)
Responda
  • Remote Authentication Dial in User Service (RADIUS)
  • Lightweight Directory Access Protocol (LDAP)
  • Local Password Authentication
  • POP3
  • Remote Password Authentication

Questão 15

Questão
Which does FortiToken use as input when generating a token code? (Choose two.)
Responda
  • User password
  • Time
  • User name
  • Seed

Questão 16

Questão
Which authentication scheme is not supported by the RADIUS implementation on FortiGate?
Responda
  • CHAP
  • MSCHAP2
  • PAP
  • FSSO

Questão 17

Questão
What protocol cannot be used with the active authentication type?
Responda
  • Local
  • RADIUS
  • LDAP
  • RSSO

Questão 18

Questão
Which user group types does FortiGate support for firewall authentication? (Choose three.)
Responda
  • RSSO
  • Firewall
  • LDAP
  • NTLM
  • FSSO

Questão 19

Questão
What is not true of configuring disclaimers on the FortiGate?
Responda
  • Disclaimers can be used in conjunction with captive portal.
  • Disclaimers appear before users authenticate.
  • Disclaimers can be bypassed through security exemption lists.
  • Disclaimers must be accepted in order to continue to the authentication login or originally intended destination.

Questão 20

Questão
When configuring LDAP on the FortiGate as a remote database for users, what is not a part of the configuration?
Responda
  • The name of the attribute that identifies each user (Common Name Identifier).
  • The user account or group element names (user DN).
  • The server secret to allow for remote queries (Primary server secret).
  • The credentials for an LDAP administrator (password).

Questão 21

Questão
Which statement best describes what SSL VPN Client Integrity Check does?
Responda
  • Blocks SSL VPN connection attempts from users that has been blacklisted.
  • Detects the Windows client security applications running in the SSL VPN client's PCs
  • Validates the SSL VPN user credential.
  • Verifies which SSL VPN portal must be presented to each SSL VPN user.
  • Verifies that the latest SSL VPN client is installed in the client's PC.

Questão 22

Questão
Which statement best describes what SSL.root is?
Responda
  • The name of the virtual network adapter required in each user's PC for SSL VPN Tunnel mode.
  • he name of a virtual interface in the root VDOM where all the SSL VPN user traffic comes from
  • A Firewall Address object that contains the IP addresses assigned to SSL VPN users.
  • The virtual interface in the root VDOM that the remote SSL VPN tunnels connect to.

Questão 23

Questão
Which of the following authentication methods can be used for SSL VPN authentication? (Choose three.)
Responda
  • Remote Password Authentication (RADIUS, LDAP)
  • Two-Factor Authentication
  • Local Password Authentication
  • FSSO
  • RSSO

Questão 24

Questão
A FortiGate is configured with the 1.1.1.1/24 address on the wan2 interface and HTTPS Administrative Access, using the default tcp port, is enabled for that interface. Given the SSL VPN settings in the exhibit. Which of the following SSL VPN login portal URLs are valid? (Choose two.)
Responda
  • http://1.1.1.1:443/Training
  • https://1.1.1.1:443/STUDENTS
  • https://1.1.1.1/login
  • https://1.1.1.1/

Questão 25

Questão
Which of the following statements are correct regarding SSL VPN Web-only mode? (Choose two.)
Responda
  • It can only be used to connect to web services.
  • IP traffic is encapsulated over HTTPS.
  • Access to internal network resources is possible from the SSL VPN portal.
  • The standalone FortiClient SSL VPN client CANNOT be used to establish a Web-only SSL VPN.
  • It is not possible to connect to SSH servers through the VPN.

Questão 26

Questão
Which statement is not correct regarding SSL VPN Tunnel mode?
Responda
  • IP traffic is encapsulated over HTTPS.
  • The standalone FortiClient SSL VPN client can be used to establish a Tunnel mode SSL VPN.
  • A limited amount of IP applications are supported.
  • The FortiGate device will dynamically assign an IP address to the SSL VPN network adapter.

Questão 27

Questão
Which of the following statements are true about IPsec VPNs? (Choose three.)
Responda
  • IPsec increases overhead and bandwidth.
  • IPsec operates at the layer 2 of the OSI model.
  • End-user's network applications must be properly pre-configured to send traffic across the IPsec VPN.
  • IPsec protects upper layer protocols.
  • IPsec operates at the layer 3 of the OSI model.

Questão 28

Questão
Which of the following statements is true regarding the differences between route-based and policy-based IPsec VPNs? (Choose two.)
Responda
  • The firewall policies for policy-based are bidirectional. The firewall policies for route-based are unidirectional.
  • In policy-based VPNs the traffic crossing the tunnel must be routed to the virtual IPsec interface. In route-based, it does not.
  • The action for firewall policies for route-based VPNs may be Accept or Deny, for policy-based VPNs it is Encrypt.
  • Policy-based VPN uses an IPsec interface, route-based does not.

Questão 29

Questão
Which of the following IPsec configuration modes can be used for implementing L2TP-over-IPSec VPNs?
Responda
  • Policy-based IPsec only.
  • Route-based IPsec only.
  • Both policy-based and route-based VPN.
  • L2TP-over-IPSec is not supported by FortiGate devices.

Questão 30

Questão
Which of the following authentication methods are supported in an IPsec phase 1? (Choose two.)
Responda
  • Asymmetric Keys
  • CA root digital certificates
  • RSA signature
  • Pre-shared keys

Questão 31

Questão
How many packets are interchanged between both IPSec ends during the negotiation of a main-mode phase 1?
Responda
  • 5
  • 3
  • 2
  • 6

Questão 32

Questão
Which of the following IPsec configuration modes can be used when the FortiGate is running in NAT mode?
Responda
  • Policy-based VPN only
  • Both policy-based and route-based VPN.
  • Route-based VPN only.
  • D. IPSec VPNs are not supported when the FortiGate is running in NAT mode.

Questão 33

Questão
Which portion of the configuration does an administrator specify the type of IPsec configuration (either policy-based or route-based)?
Responda
  • Under the IPsec VPN global settings.
  • Under the phase 2 settings.
  • Under the phase 1 settings.
  • Under the firewall policy settings.

Questão 34

Questão
Which of the following IKE modes is the one used during the IPsec phase 2 negotiation
Responda
  • Aggressive mode
  • Quick mode
  • Main mode
  • Fast mode

Questão 35

Questão
Which of the following options best defines what Diffie-Hellman is?
Responda
  • A symmetric encryption algorithm.
  • A "key-agreement" protocol.
  • A "Security-association-agreement" protocol.
  • An authentication algorithm

Questão 36

Questão
What action does an IPsec Gateway take with the user traffic routed to an IPsec VPN when it does not match any phase 2 quick mode selector?
Responda
  • Traffic is dropped.
  • Traffic is routed across the default phase 2.
  • Traffic is routed to the next available route in the routing table.
  • Traffic is routed unencrypted to the interface where the IPsec VPN is terminating.

Questão 37

Questão
An Internet browser is using the WPAD DNS method to discover the PAC file’s URL. The DNS server replies to the browser’s request with the IP address 10.100.1.10. Which URL will the browser use to download the PAC file?
Responda
  • Test FortiGate I: 07. Explicit Proxy Quiz Question 1 of 6 An Internet browser is using the WPAD DNS method to discover the PAC file’s URL. The DNS server replies to the browser’s request with the IP address 10.100.1.10. Which URL will the browser use to download the PAC file? http://10.100.1.10/proxy.pac https://10.100.1.10/ http://10.100.1.10/wpad.dat https://10.100.1.10/proxy.pac
  • https://10.100.1.10/
  • http://10.100.1.10/wpad.dat
  • https://10.100.1.10/proxy.pac

Questão 38

Questão
Which of the following statements is true regarding the TCP SYN packets that go from a client, through an implicit web proxy (transparent proxy), to a web server listening at TCP port 80? (Choose three.)
Responda
  • The source IP address matches the client IP address.
  • The source IP address matches the proxy IP address.
  • The destination IP address matches the proxy IP address.
  • The destination IP address matches the server IP addresses.
  • The destination TCP port number is 80.

Questão 39

Questão
Review the exhibit of an explicit proxy policy configuration. If there is a proxy connection attempt coming from the IP address 10.0.1.5, and from a user that has not authenticated yet, what action does the FortiGate proxy take?
Responda
  • User is prompted to authenticate. Traffic from the user Student will be allowed by the policy #1. Traffic from any other user will be allowed by the policy #2.
  • User is not prompted to authenticate. The connection is allowed by the proxy policy #2.
  • User is not prompted to authenticate. The connection will be allowed by the proxy policy #1.
  • User is prompted to authenticate. Only traffic from the user Student will be allowed. Traffic from any other user will be blocked.

Questão 40

Questão
Which protocol can an Internet browser use to download the PAC file with the web proxy configuration?
Responda
  • HTTPS
  • FTP
  • TFTP
  • HTTP

Questão 41

Questão
Which of the following are benefits of using web caching? (Choose three.)
Responda
  • Decrease bandwidth utilization
  • Reduce server load
  • Reduce FortiGate CPU usage
  • Reduce FortiGate memory usage
  • Decrease traffic delay

Questão 42

Questão
Question 6 of 6 Which of the following statements is true regarding the use of a PAC file to configure the web proxy settings in an Internet browser? (Choose two.)
Responda
  • More than one proxy is supported.
  • Can contain a list of destinations that will be exempt from the use of any proxy.
  • Can contain a list of URLs that will be exempted from the FortiGate web filtering inspection.
  • Can contain a list of users that will be exempted from the use of any proxy.

Questão 43

Questão
What is longest length of time allowed on a FortiGate device for the virus scan to complete?
Responda
  • 20 seconds
  • 30 seconds
  • 45 seconds
  • 10 seconds

Questão 44

Questão
Which type of conserve mode writes a log message immediately, rather than when the device exits conserve mode?
Responda
  • Kernel
  • Proxy
  • System
  • Device

Questão 45

Questão
Files that are larger than the oversized limit are subjected to which Antivirus check?
Responda
  • Grayware
  • Virus
  • Sandbox
  • Heuristic

Questão 46

Questão
Files reported to be infected by the "Suspicious" virus were subject to which Antivirus check?
Responda
  • Grayware
  • Virus
  • Sandbox
  • Heuristic

Questão 47

Questão
Which are the three different types of Conserve Mode that can occur on a FortiGate device? (Choose three.)
Responda
  • Proxy
  • Operating system
  • Kernel
  • System
  • Device

Questão 48

Questão
A FortiGate device is configure to perform an AV & IPS scheduled update every hour. Given the information in the exhibit, when will the next update happen?
Responda
  • 01:00
  • 02:05
  • 11:00
  • 11:08

Questão 49

Questão
What is the maximum number of different virus databases a FortiGate can have?
Responda
  • 5
  • 2
  • 3
  • 4

Questão 50

Questão
Which of the following are possible actions for static URL filtering? (Choose three.)
Responda
  • Allow
  • Block
  • Exempt
  • Warning
  • Shape

Questão 51

Questão
Which of the following are possible actions for FortiGuard web category filtering? (Choose three.)
Responda
  • Allow
  • Block
  • Exempt
  • Warning
  • Shape

Questão 52

Questão
Examine the following log message attributes and select two correct statements from the list below. (Choose two.) hostname=www.youtube.com profiletype="Webfilter_Profile" profile="default" status="passthrough" msg="URL belongs to a category with warnings enabled"
Responda
  • The traffic was blocked.
  • The user failed authentication.
  • The category action was set to warning.
  • The website was allowed.

Questão 53

Questão
Which of the following actions can be used with the FortiGuard quota feature? (Choose three.)
Responda
  • Allow
  • Block
  • Monitor
  • Warning
  • Authenticate

Questão 54

Questão
Which of the following statements are true regarding the web filtering modes? (Choose two.)
Responda
  • Proxy based mode allows for customizable block pages to display when sites are prevented.
  • Proxy based mode requires more resources than flow-based.
  • Flow based mode offers more settings under the advanced configuration section of the GUI.
  • Proxy based mode offers higher throughput than flow-based mode.

Questão 55

Questão
Which of the following web filtering modes can inspect the full URL? (Choose two.)
Responda
  • Proxy based
  • DNS based
  • Policy based
  • Flow based

Questão 56

Questão
The exhibit is a screen shot of an Application Control profile. Different settings are circled and numbered. Select the number identifying the setting which will provide additional information about YouTube access, such as the name of the video watched.
Responda
  • 1
  • 2
  • 3
  • 4
  • 5

Questão 57

Questão
Which of the following statements are true regarding application control? (Choose two.)
Responda
  • Application control is based on TCP destination port numbers.
  • Application control is proxy based.
  • Encrypted traffic can be identified by application control.
  • Traffic shaping can be applied to the detected application traffic.

Questão 58

Questão
Which answer best describes what an "Unknown Application" is?
Responda
  • All traffic that matches the internal signature for unknown applications.
  • Traffic that does not match the RFC pattern for its protocol.
  • Any traffic that does not match an application control signature.
  • A packet that fails the CRC check.

Questão 59

Questão
What actions are possible with Application Control? (Choose three.)
Responda
  • Warn
  • Allow
  • Block
  • Traffic Shaping
  • Quarantine

Questão 60

Questão
How do application control signatures update on a FortiGate device?
Responda
  • Through FortiGuard updates.
  • Upgrade the FortiOS firmware to a newer release.
  • By running the Application Control auto-learning feature.
  • Signatures are hard coded to the device and cannot be updated.

Questão 61

Questão
The exhibit shows two static routes to the same destination subnet 172.20.168.0/24. Which of the following statements correctly describes this static routing configuration? (Choose two.)
Responda
  • Both routes will show up in the routing table.
  • The FortiGate unit will evenly share the traffic to 172.20.168.0/24 between both routes.
  • Only one route will show up in the routing table.
  • The FortiGate will route the traffic to 172.20.168.0/24 only through one route.

Questão 62

Questão
Which of the following fields contained in the IP/TCP/UDP headers can be used to make a routing decision when using policy-based routing? (Choose three.)
Responda
  • Source IP address
  • TCP flags
  • Source TCP/UDP port
  • Type of service
  • Checksum

Questão 63

Questão
Which of the following statements are true regarding WAN Link Load Balancing? (Choose two.)
Responda
  • There can be only one virtual WAN Link per VDOM.
  • FortiGate can measure the quality of each link based on latency, jitter, or lost packets percentage.
  • Link health check can be performed over each link member of the virtual WAN interface.
  • Distance and priority values are configured in each link member of the virtual WAN interface.

Questão 64

Questão
The exhibit shows a FortiGate routing table. Which of the following statements are correct? (Choose two.)
Responda
  • There is only one active default route.
  • The distance value for the route to 192.168.1.0/24 is 200.
  • An IP address in the subnet 172.16.78.0/24 has been assigned to the dmz interface.
  • The FortiGate will route the traffic to 172.17.1.2 to the next hop with the IP address 192.168.11.254.

Questão 65

Questão
Which of the following statements best describes what a FortiGate does when packets match a black hole route?
Responda
  • Packets are dropped.
  • Packets are routed based on the information in the policy-based routing table.
  • An ICMP error message is sent back to the originator.
  • Packets are routed back to the originator.

Questão 66

Questão
The exhibit shows three static routes. Which static route(s) will be used to route the packets to the destination IP address 172.20.168.1?
Responda
  • The routes with the ID numbers 2 and 3.
  • Only the route with the ID number 3.
  • Only the route with the ID number 2.
  • Only the route with the ID number 1.

Questão 67

Questão
What must be configures in order to keep two static routes to the same destination in the routing table?
Responda
  • The same priority.
  • The same distance and same priority.
  • The same distance.
  • The same metric.

Questão 68

Questão
Which action does the FortiGate take when link health monitor times out?
Responda
  • All routes to the destination subnet configured in the link health monitor are removed from the routing table.
  • The distance values of all routes using the interface configured in the link health monitor are increased.
  • The priority values of all routes using the interface configured in the link health monitor are increased.
  • All routes using the next-hop gateway configured in the link health monitor are removed from the routing table.

Questão 69

Questão
In the debug command output shown in the exhibit, which of the following best describes the MAC address 00:09:0f:69:03:7e?
Responda
  • It is one of the secondary MAC addresses of the port1 interface.
  • It is the primary MAC address of the port1 interface.
  • It is the MAC address of another network device located in the same LAN segment as the FortiGate unit’s port1 interface.
  • It is the HA virtual MAC address.

Questão 70

Questão
Examine the network topology diagram in the exhibit; the workstation with the IP address 212.10.11.110 sends a TCP SYN packet to the workstation with the IP address 212.10.11.20. Which of the following sentences best describes the result of the reverse path forwarding (RPF) check executed by the FortiGate on the SYN packet? (Choose two.)
Responda
  • Packet is allowed if RPF is configured as loose.
  • Packet is allowed if RPF is configured as strict.
  • Packet is blocked if RPF is configured as loose.
  • Packet is blocked if RPF is configured as strict.

Questão 71

Questão
A FortiGate device has two VDOMs in NAT/route mode. Which of the following solutions can be implemented by a network administrator to route traffic between the two VDOMs? (Choose two.)
Responda
  • Use the inter-VDOM links automatically created between all VDOMS.
  • Manually create and configure an inter-VDOM link between your two VDOMs.
  • Interconnect and configure an external physical interface in one VDOM to another physical interface in the second VDOM.
  • Configure both VDOMs to share the same routing table.

Questão 72

Questão
Which of the following settings can be configured per VDOM? (Choose three.)
Responda
  • Operating mode (NAT/route or transparent)
  • Static routes
  • Hostname
  • System time
  • Firewall policies

Questão 73

Questão
Which of the following statements are correct regarding FortiGate virtual domains (VDOMs)? (Choose two.)
Responda
  • VDOMs divide a single FortiGate unit into two or more independent firewalls.
  • A management VDOM handles SNMP, logging, alert email, and FortiGuard updates.
  • Each VDOM can run different firmware versions.
  • Administrative users with a ‘super_admin’ profile can administrate only one VDOM.

Questão 74

Questão
Which of the following statements is correct concerning multiple VDOMs configured in a FortiGate device?
Responda
  • FortiGate devices, from the FGT/FWF 60D and above, all support VDOMS.
  • All FortiGate devices scale to 250 VDOMS.
  • Each VDOM requires its own FortiGuard license.
  • FortiGate devices support more NAT/Route VDOMs than Transparent Mode VDOMs.

Questão 75

Questão
A FortiGate device is configured with two VDOMs. The management VDOM is 'root', and is configured in transparent mode, 'vdom1' is configured as NAT/route mode. Which traffic is generated only by 'root' and not 'vdom1'? (Choose three.)
Responda
  • SNMP traps
  • FortiGuard
  • ARP
  • NTP
  • ICMP redirect

Questão 76

Questão
A FortiGate unit is operating in NAT/route mode and configured with two VLAN sub-interfaces on the same physical interface. Which of the following statement is correct regarding the VLAN IDs in this scenario?
Responda
  • The two VLAN sub-interfaces can have the same VLAN ID only if they have IP addresses in different subnets.
  • The two VLAN sub-interfaces must have different VLAN IDs.
  • The two VLAN sub-interfaces can have the same VLAN ID only if they belong to different VDOMs.
  • The two VLAN sub-interfaces can have the same VLAN ID if they are connected to different L2 IEEE 802.1Q compliant switches.

Questão 77

Questão
A FortiGate unit has multiple VDOMs in NAT/route mode with multiple VLAN interfaces in each VDOM. Which of the following statements is correct regarding the IP addresses assigned to each VLAN interface?
Responda
  • Different VLANs can share the same IP address as long as they have different VLAN IDs.
  • Different VLANs can share the same IP address as long as they are in different physical interfaces.
  • Different VLANs can share the same IP address as long as they are in different VDOMs.
  • Different VLANs can never share the same IP addresses.

Questão 78

Questão
A FortiGate device is configured with four VDOMs: 'root' and 'vdom1' are in NAT/route mode; 'vdom2' and 'vdom3' are in transparent mode. The management VDOM is 'root'. Which of the following statements are true? (Choose two.)
Responda
  • An inter-VDOM link between 'root' and 'vdom1' can be created.
  • An inter-VDOM link between 'vdom1' and 'vdom2' can be created.
  • An inter-VDOM link between 'vdom2 ' and 'vdom3' can be created.
  • Inter-VDOM link links must be manually configured for FortiGuard traffic.

Questão 79

Questão
Which of the following statements are correct differences between NAT/route and transparent mode? (Choose two.)
Responda
  • In transparent mode, interfaces do not have IP addresses.
  • Firewall policies are only used in NAT/route mode.
  • Static routes are only used in NAT/route mode.
  • Only transparent mode permits inline traffic inspection at layer 2.

Questão 80

Questão
What is the default criteria for selecting the HA master unit in a HA cluster?
Responda
  • port monitor, priority, uptime, serial number
  • port monitor, uptime, priority, serial number
  • priority, uptime, port monitor, serial number
  • uptime, priority, port monitor, serial number

Questão 81

Questão
Which of the following statements describes the objective of the gratuitous ARP packets sent by an HA cluster?
Responda
  • To synchronize the ARP tables in all the FortiGate units that are part of the HA cluster.
  • To notify the network switches that a new HA master unit has been elected.
  • To notify the master unit that the slave devices are still up and alive.
  • To notify the master unit about the physical MAC addresses of the slave units.

Questão 82

Questão
What information is synchronized between two FortiGate units that belong to the same HA cluster? (Choose three.)
Responda
  • IP addresses assigned to DHCP enabled interfaces.
  • The master device's hostname.
  • Routing configuration and state.
  • Reserved HA management interface IP configuration.
  • Firewall policies and objects.

Questão 83

Questão
What are required to be the same for two FortiGate units to form an HA cluster? (Choose two.)
Responda
  • Firmware
  • Model
  • Hostname
  • System time zone

Questão 84

Questão
Which statement describes how traffic flows in sessions handled by a slave unit in an active-active HA cluster?
Responda
  • Packets are sent directly to the slave unit using the slave physical MAC address.
  • Packets are sent directly to the slave unit using the HA virtual MAC address.
  • Packets arrive at both units simultaneously, but only the slave unit forwards the session.
  • Packets are first sent to the master unit, which then forwards the packets to the slave unit.

Questão 85

Questão
Which of the following statements correctly describes the use of the “diagnose sys ha reset-uptime” command?
Responda
  • To force an HA failover when the HA override setting is disabled.
  • To force an HA failover when the HA override setting is enabled.
  • To clear the HA counters.
  • To restart a FortiGate unit that is part of an HA cluster.

Questão 86

Questão
Which of the following statements are correct regarding a master HA unit? (Choose two.)
Responda
  • There should be only one master unit is each HA virtual cluster.
  • The master synchronizes cluster configuration with slaves.
  • Only the master has a reserved management HA interface.
  • Heartbeat interfaces are not required on a master unit.

Questão 87

Questão
Which of the following statements are correct concerning the FortiGate session life support protocol? (Choose two.)
Responda
  • By default, UDP sessions are not synchronized.
  • Up to four FortiGate devices in standalone mode are supported.
  • Only the master unit handles the traffic.
  • Allows per-VDOM session synchronization.

Questão 88

Questão
What configuration objects are automatically added when using the FortiGate's FortiClient VPN Configuration Wizard? (Choose two.)
Responda
  • Static route
  • Phase 1
  • User group
  • Phase 2

Questão 89

Questão
Which of the following statements are correct concerning IPsec dialup VPN configurations for FortiGate devices? (Choose two.)
Responda
  • Main mode must be used when there is more than one IPsec dialup VPN configure on the same FortiGate device.
  • A FortiGate device with an IPsec VPN configured as dialup can initiate the tunnel connection to any remote IP address.
  • Peer ID must be used when there is more than one aggressive-mode IPsec dialup VPN on the same FortiGate device.
  • The FortiGate will automatically add a static route to the source quick mode selector address received from each remote peer.

Questão 90

Questão
Which statement is correct concerning an IPsec VPN with the remote gateway setting configured as 'Dynamic DNS'?
Responda
  • The FortiGate will accept IPsec VPN connections from any IP address.
  • The FQDN resolution of the local FortiGate IP address where the VPN is terminated must be provided by a dynamic DNS provider.
  • The FortiGate will accept IPsec VPN connections only from IP addresses included in a dynamic DNS access list.
  • The remote gateway IP address can change dynamically.

Questão 91

Questão
The exhibit shows a part output of the diagnostic command 'diagnose debug application ike 255', taken during the establishment of a VPN. Which of the following statements are correct concerning this output? (Choose two.)
Responda
  • The quick mode selectors negotiated between both IPsec VPN peers is 0.0.0.0/32 for both the source and destination addresses.
  • The output corresponds to a phase 2 negotiation.
  • NAT-T is enabled and there is a third device in the path performing NAT of the traffic between both IPsec VPN peers.
  • The IP address of the remote IPsec VPN peer is 172.20.187.114.

Questão 92

Questão
Which of the following combinations of two FortiGate device configurations (side A and side B), can be used to successfully establish an IPsec VPN between them? (Choose two.)
Responda
  • Side A: main mode, remote gateway as static IP address, policy-based VPN. Side B: aggressive Mode, remote Gateway as static IP address, policy-based VPN.
  • Side A: main mode, remote gateway as static IP Address, policy-based VPN. Side B: main mode, remote gateway as static IP address, route-based VPN.
  • Side A: main mode, remote gateway as static IP address, route-based VPN. Side B: main mode, remote gateway as dialup, route-based VPN.
  • Side A: main mode, remote gateway as dialup, policy-based VPN. Side B: main mode, remote gateway as dialup, policy-based VPN.

Questão 93

Questão
Which of the following statements are correct concerning the IPsec phase 1 and phase 2, shown in the exhibit? (Choose two.)
Responda
  • The quick mode selector in the remote site must also be 0.0.0.0/0 for the source and destination addresses.
  • Only remote peers with the peer ID 'fortinet' will be able to establish a VPN.
  • The FortiGate device will automatically add a static route to the source quick mode selector address received from each remote VPN peer.
  • The configuration will work only to establish FortiClient-to-FortiGate tunnels. A FortiGate-to-FortiGate tunnel requires a different configuration.

Questão 94

Questão
What is required in a FortiGate configuration to have more than one dialup IPsec VPN using aggressive mode?
Responda
  • All the aggressive mode dialup VPNs MUST accept connections from the same peer ID.
  • Each peer ID MUST match the FQDN of each remote peer.
  • Each aggressive mode dialup MUST accept connections from different peer ID.
  • The peer ID setting must NOT be used.

Questão 95

Questão
Which of the following protocols are defined in the IPsec Standard? (Choose two.)
Responda
  • AH
  • GRE
  • SSL/TLS
  • ESP

Questão 96

Questão
Which of the following statements are correct concerning IKE mode config? (Choose two.)
Responda
  • It can dynamically assign IP addresses to IPsec VPN clients.
  • It can dynamically assign DNS settings to IPsec VPN clients.
  • It uses the ESP protocol.
  • It can be enabled in the phase 2 configuration.

Questão 97

Questão
You have configured the DHCP server on a FortiGate's port1 interface (or internal, depending on the model) to offer IPs in a range of 192.168.1.65-192.168.1.253. When the first host sends a DHCP request, what IP will the DHCP offer?
Responda
  • 192.168.1.99
  • 192.168.1.253
  • 192.168.1.65
  • 192.168.1.66

Questão 98

Questão
Which is not a FortiGate feature?
Responda
  • Database auditing
  • Intrusion prevention
  • Web filtering
  • Application control

Questão 99

Questão
Which UTM feature sends a UDP query to FortiGuard servers each time FortiGate scans a packet (unless the response is locally cached)?
Responda
  • Antivirus
  • VPN
  • IPS
  • Web Filtering

Questão 100

Questão
You have created a new administrator account, and assign it the prof_admin profile. Which is false about that account's permissions?
Responda
  • It cannot upgrade or downgrade firmware.
  • It can create and assign administrator accounts to parts of its own VDOM.
  • It can reset forgotten passwords for other administrator accounts such as "admin".
  • It has a smaller permissions scope than accounts with the "super_admin" profile.

Questão 101

Questão
When an administrator attempts to manage FortiGate from an IP address that is not a trusted host, what happens?
Responda
  • FortiGate will still subject that person's traffic to firewall policies; it will not bypass them.
  • FortiGate will drop the packets and not respond.
  • FortiGate responds with a block message, indicating that it will not allow that person to log in.
  • FortiGate responds only if the administrator uses a secure protocol. Otherwise, it does not respond.

Questão 102

Questão
Acme Web Hosting is replacing one of their firewalls with a FortiGate. It must be able to apply port forwarding to their back-end web servers while blocking virus uploads and TCP SYN floods from attackers. Which operation mode is the best choice for these requirements?
Responda
  • NAT/route
  • NAT mode with an interface in one-arm sniffer mode
  • Transparent mode
  • No appropriate operation mode exists

Questão 103

Questão
if you have lost your password for the "admin" account on your FortiGate, how should you reset it?
Responda
  • Log in with another administrator account that has "super_admin" profile permissions, then reset the password for the "admin" account.
  • Reboot the FortiGate. Via the local console, during the boot loader, use the menu to format the flash disk and reinstall the firmware. Then you can log in with the default password.
  • Power off the FortiGate. After several seconds, restart it. Via the local console, within 30 seconds after booting has completed, log in as "maintainer" and enter the CLI commands to set the password for the "admin" account.
  • Reboot the FortiGate. Via the local console, during the boot loader, use the menu to log in as "maintainer" and enter the CLI commands to set the password for the "admin" account.

Questão 104

Questão
A backup file begins with this line: #config-version=FGVM64-5.02-FW-build589-140613:opmode=0:vdom=0:user=admin #conf_file_ver=3881503152630288414 #buildno=0589 #global_vdom=1 Can you restore it to a FortiWiFi 60D?
Responda
  • Yes
  • Yes, but only if you replace the "#conf_file_ver" line so that it contains the serial number of that specific FortiWiFi 60D.
  • Yes, but only if it is running the same version of FortiOS, or a newer compatible version.
  • No

Questão 105

Questão
Which protocols can you use for secure administrative access to a FortiGate? (Choose two)
Responda
  • SSH
  • Telnet
  • NTLM
  • HTTPS

Questão 106

Questão
A new version of FortiOS firmware has just been released. When you upload new firmware, which is true?
Responda
  • If you upload the firmware image via the boot loader's menu from a TFTP server, it will not preserve the configuration. But if you upload new firmware via the GUI or CLI, as long as you are following a supported upgrade path, FortiOS will attempt to convert the existing configuration to be valid with any new or changed syntax.
  • No settings are preserved. You must completely reconfigure.
  • No settings are preserved. After the upgrade, you must upload a configuration backup file. FortiOS will ignore any commands that are not valid in the new OS. In those cases, you must reconfigure settings that are not compatible with the new firmware.
  • You must use FortiConverter to convert a backup configuration file into the syntax required by the new FortiOS, then upload it to FortiGate.

Questão 107

Questão
In a Crash log, what does a status of 0 indicate?
Responda
  • Abnormal termination of a process
  • A process closed for any reason
  • Normal shutdown with no abnormalities
  • DHCP process crashed

Questão 108

Questão
Which of the following are considered log types? (Choose three.)
Responda
  • Forward log
  • Traffic log
  • Syslog
  • Event log
  • Security log

Questão 109

Questão
What determines whether a log message is generated or not?
Responda
  • Firewall policy setting
  • Log Settings in the GUI
  • 'config log' command in the CLI
  • Syslog
  • Webtrends

Questão 110

Questão
Where are most of the security events logged?
Responda
  • Security log
  • Forward Traffic log
  • Event log
  • Alert log
  • Alert Monitoring Console

Questão 111

Questão
What are the ways FortiGate can monitor logs? (Choose three.)
Responda
  • MIB
  • SMS
  • Alert Emails
  • SNMP
  • FortiAnalyzer
  • Alert Message Console

Questão 112

Questão
What attributes are always included in a log header? (Choose three.)
Responda
  • policyid
  • level
  • user
  • time
  • subtype
  • duration

Questão 113

Questão
Examine this log entry. What does the log indicate? (Choose three.) date=2013-12-04 time=09:30:18 logid=0100032001 type=event subtype=system level=information vd="root" user="admin" ui=http(192.168.1.112) action=login status=success reason=none profile="super_admin" msg="Administrator admin logged in successfully from http(192.168.1.112)"
Responda
  • In the GUI, the log entry was located under “Log & Report > Event Log > User”.
  • In the GUI, the log entry was located under “Log & Report > Event Log > System”.
  • In the GUI, the log entry was located under “Log & Report > Traffic Log > Local Traffic”.
  • The connection was encrypted
  • The connection was unencrypted.
  • The IP of the FortiGate interface that “admin” connected to was 192.168.1.112.
  • The IP of the computer that “admin” connected from was 192.168.1.112.

Questão 114

Questão
To which remote device can the FortiGate send logs? (Choose three.)
Responda
  • Syslog
  • FortiAnalyzer
  • Hard drive
  • Memory
  • FortiCloud

Questão 115

Questão
What log type would indicate whether a VPN is going up or down?
Responda
  • Event log
  • Security log
  • Forward log
  • Syslog

Questão 116

Questão
There are eight (8) log severity levels that indicate the importance of an event. Not including Debug, which is only needed to log diagnostic data, what are both the lowest AND highest severity levels?
Responda
  • Notification, Emergency
  • Information, Critical
  • Error, Critical
  • Information, Emergency
  • Information, Alert

Semelhante

Segundo examen de WORD
jundraker
Prueba de mapas
LiliaRojas
Prueba
jjnavares
TEST
zidanejk
Marcas de Celulares más Reconocidas
Didier Cairasco
La cédula
José Marcilla
mapa de prueba angel
angeljv0826
mapa mental de prueba
joseangelvalenzu
Dirección Nacional de gestión de compras, inventarios y garantías
comprasnacionales
Prueba encuesta
Marco Ruiz6660