Refer to the exhibit.
While deploying a new FortiGate-VMX Security node, an administrator receives the error message shown
in the exhibit.
In this scenario, which statement is correct?
A. The NSX Manager is not able to connect on the FortiGate Service Manager RestAPI service.
B. The vCenter is not able to locate the FortiGate-VMX OVF file.
C. The FortiGate Service Manager does not have the proper permission to register the FortiGate-VMX Service.
D. The vCenter cannot connect to the FortiGate Service Manager.
A customer is experiencing problems with a legacy L3/L4 firewall device and the IPv6 SIP VoIP traffic. Their device is dropping SIP packets, consequently, it cannot process SIP voice calls.
Which solution will solve the customer's problem?
A. Replace their legacy device with a FortiGate and deploy a FortiVoice to extract information from the body of the IPv6 SIP packet.
B. Deploy a FortiVoice and enable IPv6 SIP.
C. Deploy a FortiVoice and enable an IPv6 SIP session helper.
D. Replace their legacy device with a FortiGate and configure it to extract information from the body of the IPv6 SIP packet.
Refer to the exhibit.
A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO). OSPF is used to redistribute routes between the offices. After deployment, a server with IP address 10.10.10.35 located on the DMZ network of the BO FortiGate, was reported unreachable from hosts located on the LAN network of the same FortiGate.
Referring to the exhibit, which statement is true?
A. The ICMP packets are being blocked by an implicit deny policy.
B. A directly connected subnet is being partially superseded by an OSPF redistributed subnet.
C. Enabling NAT on the VPN firewall policy will solve the problem.
D. The incoming access list should have an accept action instead of a deny action to solve the problem.
A customer has a SCADA environmental control device that is triggering a false-positive IPS alert whenever the Web GUI of the device is accessed. You cannot create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support. You need to prevent the false positive IPS alerts from occurring.
In this scenario, which two actions will accomplish this task? (Choose two.)
A. Create a URL filter with the Exempt action for that device IP address.
B. Change the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.
C. Create a very specific firewall policy for that device IP address which does not perform IPS scanning.
D. Reconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
A customer wants to integrate their on-premise FortiGate with their Azure infrastructure.
Which two components must be in place to configure the Azure Fabric connector? (Choose two.)
A. FortiGate-VM virtual appliance deployed on-premise.
B. An inbound policy from the Azure FortiGate-VM virtual appliance.
C. An outbound policy from the Azure FortiGate-VM virtual appliance.
D. A FortiGate-VM virtual appliance deployed in Azure.
Refer to the exhibit.
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
A. LAG-3 on switches on FS448D-A and FS448D-B may be connected to a single 802.3ad trunk on another device.
B. LAG-1 and LAG-2 should be connected to a 4-port single 802.3ad trunk on another device.
C. port13 and port14 on FS448D-A should be connected to port13 and port14 on FS448D-B.
D. LAG-1 and LAG-2 should be connected to a single 4-port 802.3ad interface on the FortiGate-A.
You are administering the FortiGate 5000 and FortiGate 7000 series products. You want to access the HTTPS GUI of the blade located in logical slot 3 of the secondary chassis in a high-availability cluster.
Which URL will accomplish this task?
A. https://192.168.1.99:44322
B. https://192.168.1.99:44323
C. https://192.168.1.99:44313
D. https://192.168.1.99:44302
You want to access the JSON API on FortiManager to retrieve information on an object. In this scenario, which two methods will satisfy the requirement? (Choose two.)
A. Download the WSDL file from FortiManager administration GUI.
B. Make a call with the curl utility on your workstation.
C. Make a call with the SoapUI API tool on your workstation.
D. Make a call with the Web browser on your workstation.
Refer to the exhibit.
You created a custom health-check for your FortiWeb deployment. Given the output shown in the exhibit, which statement is true?
A. The FortiWeb must receive an RST packet from the server.
B. The FortiWeb must receive an HTTP 200 response code from the server.
C. The FortiWeb must match the hash value of the page index.html.
D. The FortiWeb must receive an ICMP Echo Request from the server.
Refer to the exhibit.
You created an aggregate interface between a FortiGate and a switch consisting of two 1 Gbps links as shown in the exhibit. However, the maximum bandwidth never exceeds 1 Gbps and employees are reporting that the network is slow. After troubleshooting, you notice that only one member interface is being used. The configuration for the aggregate interface is shown in the exhibit.
In this scenario, which command will solve this problem?
A. Option A
B. Option B
C. Option C
D. Option D
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Fortinet exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your NSE8_811 exam preparations and Fortinet certification application, do not hesitate to visit our Vcedump.com to find your solutions here.