Question 1
Multiple choice
How are bulk configuration changes made using FortiManager CLI scripts? (Choose two.)
-
A
When run on the All FortiGate in ADOM, changes are automatically installed without the creation of a new revision history.
-
B
When run on the Device Database, changes are applied directly to the managed FortiGate device.
-
C
When run on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.
-
D
When run on the Policy Package, ADOM database, you must use the installation wizard to apply the changes to the managed FortiGate device
Reveal answer details
Close answer details
Correct answersC, D
ExplanationCLI scripts can be run in three different ways:Device Database: By default, a script is executed on the device database. It is recommend you run the changes on the device database (default setting), as this allows you to check what configuration changes you will send to the managed device. Once scripts are run on the device database, you can install these changes to a managed device using the installation wizard. Policy Package, ADOM database: If a script contains changes related to ADOM level objects andpolicies, you can change the default selection to run on Policy Package, ADOM database and can then be installed using the installation wizard. Remote FortiGate directly (through CLI): A script can be executed directly on the device and you don't need to install these changes using the installation wizard. As the changes are directly installed on the managed device, no option is provided to verify and check the configuration changes through FortiManager prior to executing it.
Refer to the exhibit, which contains partial output from an IKE real-time debug.  Based on the debug output, which phase 1 setting is enabled in the configuration of this VPN?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationReferences: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/320160/example-advpn-configuration First the Spoke receives SHORTCUT_OFFER, it respondes with sending shortcut-query. AT the end it receives SHORTCUT_REPLY and creates new dynamic tunnel (H2S_0_0).
Question 3
Multiple choice
View the exhibit, which contains a partial routing table, and then answer the question below.  Assuming all the appropriate firewall policies are configured, which of the following pings will FortiGate route? (Choose two.)
-
A
Source IP address 10.1.0.24, Destination IP address 10.72.3.20.
-
B
Source IP address 10.72.3.27, Destination IP address 10.1.0.52.
-
C
Source IP address 10.72.3.52, Destination IP address 10.1.0.254.
-
D
Source IP address 10.73.9.10, Destination IP address 10.72.3.15.
Reveal answer details
Close answer details
Question 4
Multiple choice
Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.  An administrator would like to test session failover between the two service provider connections. What changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)
-
A
Configure set snat-route-change enable.
-
B
Change the priority of the port2 static route to 5.
-
C
Change the priority of the port1 static route to 11.
-
D
unset snat-route-change to return it to the default setting.
Reveal answer details
Close answer details
Correct answersA, C
ExplanationExplanation: Enterprise_Firewall_7.0_Study_Guide-Online.pdf p 148-149
View the exhibit, which contains the output of a debug command, and then answer the question below.  What statement is correct about this FortiGate?
-
A
It is currently in system conserve mode because of high CPU usage.
-
B
It is currently in FD conserve mode.
-
C
It is currently in kernel conserve mode because of high memory usage.
-
D
It is currently in system conserve mode because of high memory usage.
Reveal answer details
Close answer details
Question 6
Multiple choice
Refer to the exhibit, which contains partial output from an IKE real-time debug.  Which two statements about this debug output are correct? (Choose two.)
-
A
The initiator provided remote as its IPsec peer ID.
-
B
It shows a phase 2 negotiation.
-
C
Perfect Forward Secrecy (PFS) is enabled in the configuration.
-
D
The local gateway IP address is 10.0.0.1.
Reveal answer details
Close answer details
Correct answersA, D
ExplanationExplanation: A because : received peer identifier FQDN 'remote' D because : ike 0: comes 10.0.0.2:500 -> 10.0.0.1:500
Question 7
Multiple choice
A FortiGate's portl is connected to a private network. Its port2 is connected to the Internet. Explicit web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP. Which statements are true regarding the two entries in the FortiGate session table related with this traffic? (Choose two.)
-
A
Both session have the local flag on.
-
B
The destination IP addresses of both sessions are IP addresses assigned to FortiGate's interfaces.
-
C
One session has the proxy flag on, the other one does not.
-
D
One of the sessions has the IP address of port2 as the source IP address.
Reveal answer details
Close answer details
Examine the partial output from two web filter debug commands; then answer the question below:  Based on the above outputs, which is the FortiGuard web filter category for the web site www.fgt99. com?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 9
Multiple choice
In which two ways does FortiManager function when it is deployed as a local FDS? (Choose two.)
-
A
It provides VM license validation services.
-
B
It supports rating requests from non-FortiGate devices.
-
C
It caches available firmware updates for unmanaged devices.
-
D
It can be configured as an update server, a rating server, or both.
Reveal answer details
Close answer details
Question 10
Multiple choice
Which two statements about bulk configuration changes made using FortiManager CLI scripts are correct? (Choose two.)
-
A
When run on the Device Database, you must use the installation wizard to apply the changes to the managed FortiGate device.
-
B
When run on the Remote FortiGate directly, administrators do not have the option to review the changes prior to installation.
-
C
When run on the All FortiGate in ADOM, changes are automatically installed without the creation of a new revision history.
-
D
When run on the Policy Package, ADOM database, changes are applied directly to the managed FortiGate device.
Reveal answer details
Close answer details
Correct answersA, B
ExplanationReferences: https://docs.fortinet.com/document/fortimanager/6.2.1/administration-guide/71780/cli-scripts
Question 11
Single choice
Four FortiGate devices configured for OSPF connected to the same broadcast domain. The first unit is elected as the designated router The second unit is elected as the backup designated router Under normal operation, how many OSPF full adjacencies are formed to each of the other two units?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Multiple choice
What configuration changes can reduce the memory utilization in a FortiGate? (Choose two.)
-
A
Reduce the session time to live.
-
B
Increase the TCP session timers.
-
C
Increase the FortiGuard cache time to live.
-
D
Reduce the maximum file size to inspect.
Reveal answer details
Close answer details
Question 13
Single choice
A FortiGate is configured as an explicit web proxy. Clients using this web proxy are reposting DNS errors when accessing any website. The administrator executes the following debug commands and observes that the n-dns-timeout counter is increasing:  What should the administrator check to fix the problem?
-
A
The connectivity between the FortiGate unit and the DNS server.
-
B
The connectivity between the client workstations and the DNS server.
-
C
That DNS traffic from client workstations is allowed by the explicit web proxy policies.
-
D
That DNS service is enabled in the explicit web proxy interface.
Reveal answer details
Close answer details
Question 14
Multiple choice
Which two tasks are automated using the Install Wizard on FortiManager? (Choose two.)
-
A
Preview pending configuration changes for managed devices.
-
B
Add devices to FortiManager.
-
C
Import policy packages from managed devices.
-
D
Install configuration changes to managed devices.
-
E
Import interface mappings from managed devices.
Reveal answer details
Close answer details
Correct answersA, D
Explanationhttps://help.fortinet.com/fmgr/50hlp/56/5-6-2/FortiManager_Admin_Guide/1000_Device%20Manager/1200_install_to%20devices/0400_Install%20wizard-device%20settings.htm There are 4 main wizards:Add Device: is used to add devices to central management and import their configurations. Install: is used to install configuration changes from Device Manager or Policies & Objects to themanaged devices. It allows you to preview the changes and, if the administrator doesn't agree with the changes, cancel and modify them. Import policy: is used to import interface mapping, policy database, and objects associated with the managed devices into a policy package under the Policy & Object tab. It runs with the Add Device wizard by default and may be run at any time from the managed device list. Re-install policy: is used to perform a quick install of the policy package. It doesn't give the ability to preview the changes that will be installed to the managed device.
Question 15
Single choice
Examine the output of the `get router info ospf neighbor' command shown in the exhibit; then answer the question below.  Which statements are true regarding the output in the exhibit? (Choose two.) Refer to the exhibit, which shows the output of a debug command. Which statement about the output is true?
-
A
TheOSPF routers with the IDs 0.0.0.69 and 0.0.0.117 are both designated routers for the war. l network.
-
B
The OSPF router with the ID 0.0.0.2 is the designated router for the ToRemote network.
-
C
The local FortiGate is the designated router for the wan1 network.
-
D
The interface ToRemote is a point-to-point OSPF network.
Reveal answer details
Close answer details
Correct answerD
Explanationhttps://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html
Question 16
Multiple choice
Which of the following conditions must be met for a static route to be active in the routing table? (Choose three.)
-
A
The next-hop IP address is up.
-
B
There is no other route, to the same destination, with a higher distance.
-
C
The link health monitor (if configured) is up.
-
D
The next-hop IP address belongs to one of the outgoing interface subnets.
-
E
The outgoing interface is up.
Reveal answer details
Close answer details
Correct answersC, D, E
ExplanationA configured static route only goes to routing table from routing database when all the following are met : The outgoing interface is up There is no other matching route with a lower distance. The link health monitor (if configured) is successful The next-hop IP address belongs to one of the outgoing interface subnets
Question 17
Multiple choice
View the exhibit, which contains the output of a BGP debug command, and then answer the question below.  Which of the following statements about the exhibit are true? (Choose two.)
-
A
For the peer 10.125.0.60, the BGP state of is Established.
-
B
The local BGP peer has received a total of three BGP prefixes.
-
C
Since the BGP counters were last reset, the BGP peer 10.200.3.1 has never been down.
-
D
The local BGP peer has not established a TCP session to the BGP peer 10.200.3.1.
Reveal answer details
Close answer details
Question 18
Single choice
When does a RADIUS server send an Access-Challenge packet?
-
A
The server does not have the user credentials yet.
-
B
The server requires more information from the user, such as the token code for two-factor authentication.
-
C
The user credentials are wrong.
-
D
The user account is not found in the server.
Reveal answer details
Close answer details
Question 19
Multiple choice
View the exhibit, which contains the output of a debug command, and then answer the question below.  Which of the following statements about the exhibit are true? (Choose two.)
-
A
In the network on port4, two OSPF routers are down.
-
B
Port4 is connected to the OSPF backbone area.
-
C
The local FortiGate's OSPF router ID is 0.0.0.4
-
D
The local FortiGate has been elected as the OSPF backup designated router.
Reveal answer details
Close answer details
Question 20
Multiple choice
A FortiGate is rebooting unexpectedly without any apparent reason. What troubleshooting tools could an administrator use to get more information about the problem? (Choose two.)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
What is the diagnose test application ipsmenitor 5 command used for?
-
A
To enable IPS bypass mode
-
B
To disable the IPS engine
-
C
To restart all IPS engines and monitors
-
D
To provide information regarding IPS sessions
Reveal answer details
Close answer details
Correct answerA
ExplanationExplanation: # diagnose test application ipsmonitor 5: Toggle bypass status 13: IPS session list 98: Stop all IPS engines 99: Restart all IPS engines and monitor
Question 22
Multiple choice
A corporate network allows Internet Access to FSSO users only. The FSSO user student does not have Internet access after successfully logged into the Windows AD network. The output of the `diagnose debug authd fsso list' command does not show student as an active FSSO user. Other FSSO users can access the Internet without problems. What should the administrator check? (Choose two.)
-
A
The user student must not be listed in the CA's ignore user list.
-
B
The user student must belong to one or more of the monitored user groups.
-
C
The student workstation's IP subnet must be listed in the CA's trusted list.
-
D
At least one of the student's user groups must be allowed by a FortiGate firewall policy.
Reveal answer details
Close answer details
Correct answersA, D
Explanationhttps://kb.fortinet.com/kb/documentLink.do?externalID=FD38828
Question 23
Single choice
Which statement about NGFW policy-based application filtering is true?
-
A
After the application has been identified, the kernel uses only the Layer 4 header to match the traffic.
-
B
The IPS security profile is the only security option you can apply to the security policy with the action set to ACCEPT.
-
C
After IPS identifies the application, it adds an entry to a dynamic ISDB table.
-
D
FortiGate will drop all packets until the application can be identified.
Reveal answer details
Close answer details
Question 24
Single choice
View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.  The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:  However, the IKE real time debug does not show any output. Why?
-
A
The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.
-
B
The log-filter setting was set incorrectly. The VPN's traffic does not match this filter.
-
C
The debug shows only error messages. If there is no output, then the tunnel is operating normally.
-
D
The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
Reveal answer details
Close answer details
Question 25
Multiple choice
Refer to the exhibit, which shows a partial routing table.  Assuming all the appropriate firewall policies are configured, which two pings will FortiGate route? (Choose two.)
-
A
Source IP address: 10.1.0.10. Destination IP address: 10.64.1.52
-
B
Source IPaddress: 10.72.3.52. Destination IP address: 10.1.0.254
-
C
Source IPaddress: 10.10.4.24, Destination IPaddress: 10.72.3.20
-
D
Source IPaddress: 10.73.9.10, Destination IPaddress: 10.72.3.15
Reveal answer details
Close answer details
|