Question 1
Multiple choice
Which two VDOMs are the default VDOMs created when FortiGate is set up in split VDOM mode? (Choose two.)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answersA, D
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/758820/split-task-vdom-mode
Refer to the exhibits.   The exhibits show the SSL and authentication policy (Exhibit A) and the security policy (Exhibit B) tor Facebook. Users are given access to the Facebook web application. They can play video content hosted on Facebook but they are unable to leave reactions on videos or other types of posts. Which part of the policy configuration must you change to resolve the issue?
-
A
The SSL inspection needs to be a deep content inspection.
-
B
Force access to Facebook using the HTTP service.
-
C
Additional application signatures are required to add to the security policy.
-
D
Add Facebook in the URL category in the security policy.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe lock logo behind Facebook_like.Button indicates that SSL Deep Inspection is Required.
Question 3
Multiple choice
Refer to the exhibit showing a debug flow output.  Which two statements about the debug flow output are correct? (Choose two.)
-
A
The debug flow is of ICMP traffic.
-
B
A firewall policy allowed the connection.
-
C
A new traffic session is created.
-
D
The default route is required to receive a reply.
Reveal answer details
Close answer details
Correct answersA, C
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/54688/debugging-the-packet-flow
Question 4
Multiple choice
Which two statements are true about collector agent advanced mode? (Choose two.)
-
A
Advanced mode uses Windows convention--NetBios: Domain\Username.
-
B
FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate
-
C
Advanced mode supports nested or inherited groups
-
D
Security profiles can be applied only to user groups, not individual users.
Reveal answer details
Close answer details
Correct answersB, C
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/482937/agent-based-fsso
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
-
A
-
B
Intrusion prevention system engine
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: http://docs.fortinet.com/document/fortigate/6.0.0/handbook/240599/application-control
Which statement is correct regarding the inspection of some of the services available by web applications embedded in third-party websites?
-
A
The security actions applied on the web applications will also be explicitly applied on the third-party websites.
-
B
The application signature database inspects traffic only from the original web application server.
-
C
FortiGuard maintains only one signature of each web application that is unique.
-
D
FortiGate can inspect sub-application traffic regardless where it was originated.
Reveal answer details
Close answer details
Correct answerD
ExplanationReferences: https://help.fortinet.com/fortiproxy/11/Content/Admin%20Guides/FPX-AdminGuide/300_System/303d_FortiGuard.htm
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?
-
A
DNS-based web filter and proxy-based web filter
-
B
Static URL filter, FortiGuard category filter, and advanced filters
-
C
Static domain filter, SSL inspection filter, and external connectors filters
-
D
FortiGuard category filter and rating filter
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://fortinet121.rssing.com/chan-67705148/all_p1.html
When browsing to an internal web server using a web-mode SSL VPN bookmark, which IP address is used as the source of the HTTP request?
-
A
remote user's public IP address
-
B
The public IP address of the FortiGate device.
-
C
The remote user's virtual IP address.
-
D
The internal IP address of the FortiGate device.
Reveal answer details
Close answer details
Correct answerD
ExplanationSource IP seen by the remote resources is FortiGate's internal IP address and not the user's IP address
Question 9
Multiple choice
Which of the following statements about central NAT are true? (Choose two.)
-
A
IP tool references must be removed from existing firewall policies before enabling central NAT.
-
B
Central NAT can be enabled or disabled from the CLI only.
-
C
Source NAT, using central NAT, requires at least one central SNAT policy.
-
D
Destination NAT, using central NAT, requires a VIP object as the destination address in a firewall.
Reveal answer details
Close answer details
Question 10
Multiple choice
Which statements are true regarding firewall policy NAT using the outgoing interface IP address with fixed port disabled? (Choose two.)
-
A
This is known as many-to-one NAT.
-
B
Source IP is translated to the outgoing interface IP.
-
C
Connections are tracked using source port and source MAC address.
-
D
Port address translation is not used.
Reveal answer details
Close answer details
Question 11
Multiple choice
Refer to the exhibit.  An administrator is running a sniffer command as shown in the exhibit. Which three pieces of information are included in the sniffer output? (Choose three.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answersA, C, E
ExplanationReferences: https://kb.fortinet.com/kb/documentLink.do?externalID=11186
Question 12
Single choice
Refer to the exhibit.  The exhibit shows a CLI output of firewall policies, proxy policies, and proxy addresses. How does FortiGate process the traffic sent to http://www.fortinet.com?
-
A
Traffic will be redirected to the transparent proxy and it will be allowed by proxy policy ID 3.
-
B
Traffic will not be redirected to the transparent proxy and it will be allowed by firewall policy ID 1.
-
C
Traffic will be redirected to the transparent proxy and It will be allowed by proxy policy ID 1.
-
D
Traffic will be redirected to the transparent proxy and it will be denied by the proxy implicit deny policy.
Reveal answer details
Close answer details
Question 13
Single choice
Refer to the exhibit.  The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?
-
A
-
B
Enable restrict access to trusted hosts
-
C
Change Administrator profile
-
D
Enable two-factor authentication
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://kb.fortinet.com/kb/documentLink.do?externalID=FD34502
Question 14
Single choice
If Internet Service is already selected as Source in a firewall policy, which other configuration objects can be added to the Source filed of a firewall policy?
-
A
-
B
Once Internet Service is selected, no other object can be added
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.2.5/cookbook/179236/using-internet-service-in-policy
Question 15
Multiple choice
In which two ways can RPF checking be disabled? (Choose two )
-
A
Enable anti-replay in firewall policy.
-
B
Disable the RPF check at the FortiGate interface level for the source check
-
C
Enable asymmetric routing.
-
D
Disable strict-arc-check under system settings.
Reveal answer details
Close answer details
Correct answersC, D
ExplanationReferences: https://kb.fortinet.com/kb/documentLink.do?externalID=FD33955
Question 16
Multiple choice
Which two statements about FortiGate FSSO agentless polling mode are true? (Choose two.)
-
A
FortiGate uses the AD server as the collector agent.
-
B
FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
-
C
FortiGate does not support workstation check.
-
D
FortiGate directs the collector agent to use a remote LDAP server.
Reveal answer details
Close answer details
Correct answersB, D
ExplanationReferences: https://kb.fortinet.com/kb/documentLink.do?externalID=FD47732
Question 17
Multiple choice
Which three statements about security associations (SA) in IPsec are correct? (Choose three.)
-
A
Phase 2 SAs are used for encrypting and decrypting the data exchanged through the tunnel.
-
B
-
C
A phase 1 SA is bidirectional, while a phase 2 SA is directional.
-
D
Phase 2 SA expiration can be time-based, volume-based, or both.
-
E
Both the phase 1 SA and phase 2 SA are bidirectional.
Reveal answer details
Close answer details
Question 18
Multiple choice
Refer to the FortiGuard connection debug output.  Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
-
A
A local FortiManager is one of the servers FortiGate communicates with.
-
B
One server was contacted to retrieve the contract information.
-
C
There is at least one server that lost packets consecutively.
-
D
FortiGate is using default FortiGuard communication settings.
Reveal answer details
Close answer details
Question 19
Single choice
Which of statement is true about SSL VPN web mode?
-
A
The tunnel is up while the client is connected.
-
B
It supports a limited number of protocols.
-
C
The external network application sends data through the VPN.
-
D
It assigns a virtual IP address to the client.
Reveal answer details
Close answer details
Correct answerB
ExplanationFortiGate_Security_6.4 page 575 - Web mode requires only a web browser, but supports a limited number of protocols.
Question 20
Single choice
By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers. Which CLI command will cause FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering?
-
A
set fortiguard-anycast disable
-
B
set webfilter-force-off disable
-
C
set webfilter-cache disable
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://kb.fortinet.com/kb/documentLink.do?externalID=FD48294
Question 21
Multiple choice
Which three options are the remote log storage options you can configure on FortiGate? (Choose three.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answersB, C, E
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/265052/logging-and-reporting-overview
Question 22
Multiple choice
Which two types of traffic are managed only by the management VDOM? (Choose two.)
-
A
FortiGuard web filter queries
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 23
Single choice
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?
-
A
The browser requires a software update.
-
B
FortiGate does not support full SSL inspection when web filtering is enabled.
-
C
The CA certificate set on the SSL/SSH inspection profile has not been imported into the browser.
-
D
There are network connectivity issues.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://kb.fortinet.com/kb/documentLink.do?externalID=FD41394
Question 24
Multiple choice
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.)
-
A
The interface has been configured for one-arm sniffer.
-
B
The interface is a member of a virtual wire pair.
-
C
The operation mode is transparent.
-
D
The interface is a member of a zone.
-
E
Captive portal is enabled in the interface.
Reveal answer details
Close answer details
Correct answersA, B, C
Explanationhttps://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWirePair.htm
Question 25
Single choice
Which statement about video filtering on FortiGate is true?
-
A
Full SSL Inspection is not required.
-
B
It is available only on a proxy-based firewall policy.
-
C
It inspects video files hosted on file sharing services.
-
D
Video filtering FortiGuard categories are based on web filter FortiGuard categories.
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://docs.fortinet.com/document/fortigate/7.0.0/new-features/190873/video-filtering
Question 26
Single choice
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?
-
A
Policy lookup will be disabled.
-
B
By Sequence view will be disabled.
-
C
Search option will be disabled
-
D
Interface Pair view will be disabled.
Reveal answer details
Close answer details
Correct answerD
Explanationhttps://kb.fortinet.com/kb/documentLink.do?externalID=FD47821
|