When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
-
A
-
B
Universally Unique Identifier
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationFortiGate Security 7.2 Study Guide (p.67): "When creating firewall objects or policies, a universally unique identifier (UUID) attribute is added so that logs can record these UUIDs and improve functionality when integrating with FortiManager or FortiAnalyzer." References: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/554066/firewall-policies
Question 2
Multiple choice
Refer to the exhibit.  Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)
-
A
The port3 default route has the lowest metric.
-
B
The port1 and port2 default routes are active in the routing table.
-
C
The ports default route has the highest distance.
-
D
There will be eight routes active in the routing table.
Reveal answer details
Close answer details
Correct answersB, C
Explanationhttps://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-identify-Inactive-Routes-in-the-Routing/ta-p/197595
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 4
Multiple choice
Which three authentication timeout types are availability for selection on FortiGate? (Choose three.)
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Correct answersA, D, E
Explanationhttps://kb.fortinet.com/kb/documentLink.do?externalID=FD37221
Question 5
Multiple choice
FortiGuard categories can be overridden and defined in different categories. To create a web rating override for example.com home page, the override must be configured using a specific syntax. Which two syntaxes are correct to configure web rating for the home page? (Choose two.)
-
A
-
B
-
C
-
D
www.example.com/index.html
Reveal answer details
Close answer details
Correct answersB, C
ExplanationWhen using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names - no URLs or wildcard characters are allowed. OK: google.com or www.google.com NO OK: www.google.com/index.html or google.* FortiGate_Security_6.4 page 384 When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names-- "no URLs or wildcard characters are allowed".
Examine this output from a debug flow:  Why did the FortiGate drop the packet?
-
A
The next-hop IP address is unreachable.
-
B
It failed the RPF check .
-
C
It matched an explicitly configured firewall policy with the action DENY.
-
D
It matched the default implicit firewall policy.
Reveal answer details
Close answer details
Correct answerD
Explanationhttps://kb.fortinet.com/kb/documentLink.do?externalID=13900 https://www.fortinetguru.com/2016/03/what-is-policy-id-0-and-why-lot-of-denied-traffic-on-this-policy/
Question 7
Multiple choice
Which two statements are correct regarding FortiGate HA cluster virtual IP addresses? (Choose two.)
-
A
Heartbeat interfaces have virtual IP addresses that are manually assigned.
-
B
A change in the virtual IP address happens when a FortiGate device joins or leaves the cluster.
-
C
Virtual IP addresses are used to distinguish between cluster members.
-
D
The primary device in the cluster is always assigned IP address 169.254.0.1.
Reveal answer details
Close answer details
Question 8
Multiple choice
Which two statements ate true about the Security Fabric rating? (Choose two.)
-
A
It provides executive summaries of the four largest areas of security focus.
-
B
Many of the security issues can be fixed immediately by clicking Apply where available.
-
C
The Security Fabric rating must be run on the root FortiGate device in the Security Fabric.
-
D
The Security Fabric rating is a free service that comes bundled with alt FortiGate devices.
Reveal answer details
Close answer details
Correct answersB, C
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/292634/security-rating
Question 9
Multiple choice
Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network and the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet.  Based on the information shown in the exhibit, which three configuration changes should the administrator make to fix the connectivity issue for PC3? (Choose three.)
-
A
In the IP pool configuration, set type to overload. Most Voted
-
B
Configure 192.2.0.12/24 as the secondary IP address on port1.
-
C
In the firewall policy configuration, disable ippool. Most Voted
-
D
In the IP pool configuration, set endip to 192.2.0.12. Most Voted
-
E
Configure another firewall policy that matches only the address of PC3 as source, and then place the policy on top of the list.
Reveal answer details
Close answer details
Question 10
Single choice
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationFortiGate Security 7.2 Study Guide (p.15): "When using FortiGuard servers for DNS, FortiOS uses DNS over TLS (DoT) by default to secure the DNS traffic." When using FortiGuard servers for DNS, FortiOS defaults to using DNS over TLS (DoT) to secure the DNS traffic 1. DNS over TLS is a protocol that encrypts and authenticates DNS queries and responses using the Transport Layer Security (TLS) protocol 2. This prevents eavesdropping, tampering, and spoofing of DNS data by third parties. The default FortiGuard DNS servers are 96.45.45.45 and 96.45.46.46, and they use the hostname globalsdns.fortinet.net 1. The FortiGate verifies the server hostname using the server-hostname setting in the system dns configuration 1.
Question 11
Multiple choice
FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface. In this scenario, what are two requirements for the VLAN ID? (Choose two.)
-
A
The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
-
B
The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.
-
C
The two VLAN subinterfaces must have different VLAN IDs.
-
D
The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
Reveal answer details
Close answer details
Correct answersB, C
Explanationhttps://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-use-emac-vlan-to-share-the-same-VLAN/ta-p/192843?externalID=FD43883 When FortiGate is operating in NAT mode, it means that it uses network address translation (NAT) to modify the source or destination IP addresses of the traffic passing through it1. NAT mode allows FortiGate to hide the IP addresses of the internal network from the external network, and to conserve IP addresses by using a single public IP address for multiple private IP addresses 1. A virtual LAN (VLAN) subinterface is a logical interface that allows traffic from different VLANs to enter and exit the FortiGate unit 2. A VLAN subinterface is created by adding a VLAN ID to a physical interface or an aggregate interface 2. A VLAN ID is a numerical identifier that distinguishes one VLAN from another 2. In this scenario, there are two requirements for the VLAN ID of the VLAN subinterfaces added to the same physical interface: The two VLAN subinterfaces must have different VLAN IDs. This is because the VLAN ID is used to tag the traffic with the appropriate VLAN information, and to separate the traffic into different VLANs2. If the two VLAN subinterfaces have the same VLAN ID, they will not be able to distinguish the traffic from each other, and they will not be able to forward the traffic to the correct destination. The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs. This is because VDOMs are virtual instances of FortiGate that can have their own interfaces, policies, and routing tables 3. Each VDOM operates independently from other VDOMs, and can have its own VLAN subinterfaces with different or identical VLAN IDs3. However, this requires inter-VDOM links to allow traffic between different VDOMs3.
Question 12
Multiple choice
What are two functions of the ZTNA rule? (Choose two.)
-
A
It redirects the client request to the access proxy.
-
B
It applies security profiles to protect traffic.
-
C
It defines the access proxy.
-
D
It enforces access control.
Reveal answer details
Close answer details
Correct answersB, D
ExplanationA ZTNA rule is a policy that enforces access control and applies security profiles to protect traffic between the client and the access proxy 1. A ZTNA rule defines the following parameters1: Incoming interface: The interface that receives the client request. Source: The address and user group of the client. ZTNA tag: The tag that identifies the domain that the client belongs to. ZTNA server: The server that hosts the access proxy. Destination: The address of the application that the client wants to access. Action: The action to take for the traffic that matches the rule. It can be accept, deny, or redirect. Security profiles: The security features to apply to the traffic, such as antivirus, web filter, application control, and so on. A ZTNA rule does not redirect the client request to the access proxy. That is the function of a policy route that matches the ZTNA tag and sends the traffic to the ZTNA server 2. A ZTNA rule does not define the access proxy. That is done by creating a ZTNA server object that specifies the IP address, port, and certificate of the access proxy 3. FortiGate Infrastructure 7.2 Study Guide (p.177): "A ZTNA rule is a proxy policy used to enforce access control. You can define ZTNA tags or tag groups to enforce zero-trust role-based access. To create a rule, type a rule name, and add IP addresses and ZTNA tags or tag groups that are allowed or blocked access. You also select the ZTNA server as the destination. You can also apply security profiles to protect this traffic."
Question 13
Single choice
Refer to the exhibit.  Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
-
A
The signature setting uses a custom rating threshold.
-
B
The signature setting includes a group of other signatures.
-
C
Traffic matching the signature will be allowed and logged.
-
D
Traffic matching the signature will be silently dropped and logged.
Reveal answer details
Close answer details
Correct answerD
ExplanationSelect Block to silently drop traffic matching any of the signatures included in the entry. So, while the default action would be 'Pass' for this signature the administrator is specifically overriding that to set the Block action. To use the default action the setting would have to be 'Default'. Action is drop, signature default action is listed only in the signature, it would only match if action was set to default.
Question 14
Single choice
Refer to the exhibit to view the firewall policy.  Why would the firewall policy not block a well-known virus, for example eicar?
-
A
Web filter is not enabled on the firewall policy to complement the antivirus profile.
-
B
The firewall policy is not configured in proxy-based inspection mode.
-
C
The firewall policy does not apply deep content inspection.
-
D
The action on the firewall policy is not set to deny.
Reveal answer details
Close answer details
Question 15
Single choice
An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What must the administrator do to achieve this objective?
-
A
The administrator must register the same FortiToken on more than one FortiGate device.
-
B
The administrator must use the user self-registration server.
-
C
The administrator must use a FortiAuthenticator device.
-
D
The administrator must use a third-party RADIUS OTP server.
Reveal answer details
Close answer details
Question 16
Single choice
Which of statement is true about SSL VPN web mode?
-
A
The tunnel is up while the client is connected.
-
B
It supports a limited number of protocols.
-
C
The external network application sends data through the VPN.
-
D
It assigns a virtual IP address to the client.
Reveal answer details
Close answer details
Correct answerB
ExplanationFortiGate_Security_6.4 page 575 - Web mode requires only a web browser, but supports a limited number of protocols.
Question 17
Single choice
Refer to the exhibit.  Based on the administrator profile settings, what permissions must the administrator set to run the diagnose firewall auth list CLI command on FortiGate?
-
A
Custom permission for Network
-
B
Read/Write permission for Log & Report
-
C
CLI diagnostics commands permission
-
D
Read/Write permission for Firewall
Reveal answer details
Close answer details
Correct answerC
Explanationhttps://kb.fortinet.com/kb/documentLink.do?externalID=FD50220
Question 18
Single choice
Refer to the exhibit. The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router. When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.  Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?
-
A
Configure a loopback interface with address 203.0.113.2/32.
-
B
In the VIP configuration, enable arp-reply.
-
C
Enable port forwarding on the server to map the external service port to the internal service port.
-
D
In the firewall policy configuration, enable match-vip.
Reveal answer details
Close answer details
Correct answerB
ExplanationFortiGate Security 7.2 Study Guide (p.115): "Enabling ARP reply is usually not required in most networks because the routing tables on the adjacent devices contain the correct next hop information, so the networks are reachable. However, sometimes the routing configuration is not fully correct, and having ARP reply enabled can solve the issue for you. For this reason, it's a best practice to keep ARP reply enabled."
Question 19
Single choice
Refer to the exhibit. The exhibit shows the output of a diagnose command.  What does the output reveal about the policy route?
-
A
It is an ISDB route in policy route.
-
B
It is a regular policy route.
-
C
It is an ISDB policy route with an SDWAN rule.
-
D
It is an SDWAN rule in policy route.
Reveal answer details
Close answer details
Correct answerD
ExplanationFortiGate Infrastructure 7.2 Study Guide (p.59): "ISDB routes and SD-WAN rules are assigned an ID higher than 65535. However, SD-WAN rule entries include the vwl_service field, and ISDB route entries don't."
Question 20
Single choice
Refer to the exhibit.     The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port3) interface has the IP address 10.0. 1.254/24. A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0. 1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Multiple choice
Refer to the exhibits. The exhibits show a network diagram and firewall configurations. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. Remote-User1 must be able to access the Webserver. Remote-User2 must not be able to access the Webserver.   In this scenario, which two changes can the administrator make to deny Webserver access for Remote- User2? (Choose two.)
-
A
Disable match-vip in the Deny policy.
-
B
Set the Destination address as Deny_IP in the Allow-access policy.
-
C
Enable match vip in the Deny policy.
-
D
Set the Destination address as Web_server in the Deny policy.
Reveal answer details
Close answer details
Correct answersB, C
Explanationhttps://community.fortinet.com/t5/FortiGate/Technical-Tip-Firewall-does-not-block-incoming-WAN-to-LAN/ta-p/189641 The exhibits show a network diagram and firewall configurations for a FortiGate unit that has two policies: Allow_access and Deny. The Allow_access policy allows traffic from the WAN (port1) interface to the LAN (port3) interface with the destination address of VIP and the service of HTTPS. The VIP object maps the external IP address 10.200.1.10 and port 10443 to the internal IP address 10.0.1.10 and port 443 of the Webserver. The Deny policy denies traffic from the WAN (port1) interface to the LAN (port3) interface with the source address of Deny_IP and the destination address of All. In this scenario, the administrator wants to deny Webserver access for Remote-User2, who has the IP address 10.200.3.2, which is included in the Deny_IP address object. Remote- User1, who has the IP address 10.200.3.1, must be able to access the Webserver. To achieve this goal, the administrator can make two changes to deny Webserver access for Remote-User2: Set the Destination address as Webserver in the Deny policy. This will make the Deny policy more specific and match only the traffic that is destined for the Webserver's internal IP address, instead of any destination address. Enable match-vip in the Deny policy. This will make the Deny policy apply to traffic that matches a VIP object, instead of ignoring it1. This way, the Deny policy will block Remote-User2's traffic that uses the VIP object's external IP address and port.
Question 22
Multiple choice
View the exhibit.  Which of the following statements are correct? (Choose two.)
-
A
This setup requires at least two firewall policies with the action set to IPsec.
-
B
Dead peer detection must be disabled to support this type of IPsec setup.
-
C
The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
-
D
This is a redundant IPsec setup.
Reveal answer details
Close answer details
Correct answersC, D
Explanationhttps://docs.fortinet.com/document/fortigate/6.2.4/cookbook/632796/ospf-with-ipsec-vpn-for-network-redundancy
Question 23
Single choice
Refer to the web filter raw logs.  Based on the raw logs shown in the exhibit, which statement is correct?
-
A
Social networking web filter category is configured with the action set to authenticate.
-
B
The action on firewall policy ID 1 is set to warning.
-
C
Access to the social networking web filter category was explicitly blocked to all users.
-
D
The name of the firewall policy is all_users_web.
Reveal answer details
Close answer details
Question 24
Single choice
Which statement is correct regarding the security fabric?
-
A
FortiManager is one of the required member devices.
-
B
FortiGate devices must be operating in NAT mode.
-
C
A minimum of two Fortinet devices is required.
-
D
FortiGate Cloud cannot be used for logging purposes.
Reveal answer details
Close answer details
Correct answerB
ExplanationFortiGate Security 7.2 Study Guide (p.428): "You must have a minimum of two FortiGate devices at the core of the Security Fabric, plus one FortiAnalyzer or cloud logging solution. FortiAnalyzer Cloud or FortiGate Cloud can act as the cloud logging solution. The FortiGate devices must be running in NAT mode."
Question 25
Single choice
Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up.  Based on the phase 2 configuration shown in the exhibit, which configuration change will bring phase 2 up?
-
A
On Remote-FortiGate, set Seconds to 43200.
-
B
On HQ-FortiGate, set Encryption to AES256.
-
C
On HQ-FortiGate, enable Diffie-Hellman Group 2.
-
D
On HQ-FortiGate, enable Auto-negotiate.
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/168495
Question 26
Single choice
Refer to the exhibits. Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The administrator disabled the WebServer firewall policy.   Which IP address will be used to source NAT the traffic, if a user with address 10.0.1.10 connects over SSH to the host with address 10.200.3.1?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationTraffic is coming from LAN to WAN, matches policy Full_Access which has NAT enable, so traffic uses source IP address of outgoing interface. Simple SNAT.
Question 27
Single choice
What is a reason for triggering IPS fail open?
-
A
The IPS socket buffer is full and the IPS engine cannot process additional packets.
-
B
The IPS engine cannot decode a packet.
-
C
The IPS engine is upgraded.
-
D
The administrator enabled NTurbo acceleration.
Reveal answer details
Close answer details
Question 28
Multiple choice
What are two scanning techniques supported by FortiGate? (Choose two.)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|