FG2024

FG2024

University

14 Qs

quiz-placeholder

Similar activities

Поняття ІоТ платформи

Поняття ІоТ платформи

University

9 Qs

DPMQ2

DPMQ2

University

15 Qs

Introduction to Computer Programming

Introduction to Computer Programming

University

11 Qs

Data Structures and Algorithms Quiz

Data Structures and Algorithms Quiz

University

14 Qs

Fundamentals

Fundamentals

7th Grade - University

12 Qs

Penilaian Operasi Komputer Dasar

Penilaian Operasi Komputer Dasar

7th Grade - University

10 Qs

FG2024

FG2024

Assessment

Quiz

Information Technology (IT)

University

Hard

Created by

Oriol Lorenzo

Used 5+ times

FREE Resource

14 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

5 mins • 1 pt

What is the primary FortiGate election process when the HA override setting is disabled?

Connected monitored ports > Priority > System uptime > FortiGate serial number

Connected monitored ports > System uptime > Priority > FortiGate serial number

Connected monitored ports > Priority > HA uptime > FortiGate serial number

Connected monitored ports > HA uptime > Priority > FortiGate serial number

2.

MULTIPLE CHOICE QUESTION

5 mins • 1 pt

Media Image

Refer to the exhibits, which show the firewall policy and an antivirus profile configuration

Why is the user unable to receive a block replacement message when downloading an infected file for the first time?

The intrusion prevention security profile must be enabled when using flow-based inspection mode

The option to send files to FortiSandbox for inspection is enabled

The firewall policy performs a full content inspection on the file.

Flow-based inspection is used, which resets the last packet to the user

Answer explanation

Media Image

3.

MULTIPLE CHOICE QUESTION

5 mins • 1 pt

Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.)

If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode

If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based

If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP

If SD-WAN is disabled, you configure the load balancing algorithm in config system settings

Answer explanation

Media Image

ECMP

Same-protocol routes with equal:

Destination subnet

Distance

Metric

Priority

4.

MULTIPLE CHOICE QUESTION

5 mins • 1 pt

Media Image

FortiGate is configured for firewall authentication. When attempting to access an external website, the user is not presented with a login prompt.

What is the most likely reason for this situation?

The Service DNS is required in the firewall policy

The user is using an incorrect user name

The Remote-users group is not added to the Destination

No matching user account exists for this user

Answer explanation

La política de tallafoc ha de permetre com a mínim un protocol compatible (HTTP, HTTPS, FTP o Telnet) per poder redirigir l’usuari a la pàgina d’autenticació del FortiGate.

També ha de permetre DNS, perquè l’usuari pugui resoldre noms de host i així generar trànsit inicial cap a la web de validació.

El DNS és essencial tant abans de l’autenticació (per fer la petició inicial) com després si l’autenticació falla, per permetre nous intents.

Recorda que HTTP (TCP 80) no inclou el servei DNS (UDP 53), cal declarar explícitament DNS a la política.

5.

MULTIPLE SELECT QUESTION

5 mins • 1 pt

Media Image

A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 failed to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.

Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes can the administrator make to bring phase 1 up? (Choose two.)

On HQ-FortiGate, disable Diffie-Helman group 2

On Remote-FortiGate, set port2 as Interface.

On both FortiGate devices, set Dead Peer Detection to On Demand

On HQ-FortiGate, set IKE mode to Main (ID protection)

6.

MULTIPLE SELECT QUESTION

5 mins • 1 pt

Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.)

Pre-shared key and certificate signature as authentication methods

Extended authentication (XAuth) to request the remote peer to provide a username and password

Extended authentication (XAuth) for faster authentication because fewer packets are exchanged

No certificate is required on the remote peer when you set the certificate signature as the authentication method

7.

MULTIPLE CHOICE QUESTION

5 mins • 1 pt

Media Image

Review the intrusion prevention system (IPS) profile signature settings shown in the exhibit.

What do you conclude when adding the FTP.Login.Failed signature to the IPS sensor profile?

Traffic matching the signature will be allowed and logged

The signature setting uses a custom rating threshold

The signature setting includes a group of other signatures

Traffic matching the signature will be silently dropped and logged

Create a free account and access millions of resources

Create resources
Host any resource
Get auto-graded reports
or continue with
Microsoft
Apple
Others
By signing up, you agree to our Terms of Service & Privacy Policy
Already have an account?