wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

dibujitos

Total questions: 31

Worksheet time: 19mins

Name
Class
Date
1.

the root and the_internet vdoms are configured in nat mode the dmz and local vdoms are configured in tranparent mode. the root vdom is the management vdom the to_internet vdom allows lan users to access the internet.the to_internet vdom is the only vdom with internet access and is directly connected to ISP modem. which statement is true?

a)

inter-vdom links are not requiered between the root and to_internet vdoms and to_internet vdoms because the root vdoms is used only as a management vdom

b)

inter-vdom links are required to allow traffic between the local and dmz vdoms

c)

inter-vdom links are required to allow traffic between the local and root vdoms

d)

a static route is required on the to_internet vdom to allow lan users to access the internet

2.

review the intrusion prevention system(ips) profile signature settings. which statement is correct in adding the ftp.login.failed signature to the ips sensor profile?3

a)

traffic matching the signature will be allowed and logged

b)

traffic matching the signature will be silently dropped and logged

c)

the signature setting uses a custom rating threshold,

d)

the signature setting includes a group of other signatures

3.

refer to the exhibit to view the firewall policy. which statement is correct it if well-known viruses are not being blocked?5

a)

the firewall policy does not apply deep content inspection

b)

the action on the firewall policy must be set to deny

c)

web filter should be enable on the firewall policy to complement the antivirus profile

d)

the firewall policy must be configured in proxy-based inspection mode

4.

the exhibit contains a network diagram, central snat policy, and IP pool configuration. the WAN(port1) interfaces has the ip address 10.200.1.1/24. the lan(port3) interfaces has the IP address 10.0.1.254/24. a firewall policy is configured to allow all destination from................7

a)

10.200.1.99

b)

10.200.1.49

c)

10.200.1.149

d)

10.200.1.1

5.

based on the raw log, which two statements are correct? choose two.8

a)

traffic is blocked because action is set to DENY in the firewall policy

b)

log severity is set to error on fortigate

c)

traffic belongs to the root VDOM

d)

this is a security log

6.

based on the administrator profile settings what permissions must the administrator set to run the diagnose firewall auth list CLI command on foritgate?

a)

read/write permission for log & report

b)

read/write permission for firewall

c)

custom premission for network

d)

CLI diagnostics commands permission

7.

the exhibit contains a network diagram, firewall policies, and a firewall address object configuration. an administrator created a deny policy with default settings to deny webserver access for remote user2 remote-user2 is still able to access webserver. which two changes can the administrator make to deny webserver access for remote-user2?choose two.10

a)

disable match-vip in the Deny policy

b)

enable match-vip in the deny policy

c)

set the destination address as web server in the deny policy

d)

set the destination address as deny. ip in the allow-access policy

8.

refer to the exhibit, which contains a static route configuration. an administrator created a static route for amazon web services. what CLI command must the administrator use to view the route?11

a)

diagnose firewall proute list

b)

get router info routing-table database

c)

get internet-service route list

d)

get router info routing-table all

9.

in the network shown in the exhibit, the client cannot connect to the HTTP web server. the administrator runs the fortigate built-in sniffer and gets the output as shown in the exhibit. what should the administrator do next to troublesshot the problem? 12

a)

execute a debug flow

b)

execute another sniffer in the fortigate, this time with the filter "host 10.0.1.10"

c)

run a sniffer on the web server

d)

capture the traffic using an external sniffer connected to port1

10.

why did fortigate drop the packet?19

a)

it failed the RPF check

b)

the next-hop IP address is unreachable

c)

it matched the default implicit firewall policy

d)

it matched an explicitly configured firewall policy with the action DENY

11.

refer to the exhibit to view the application control profile. based on the configuration, what will happen to apple face time?26

a)

apple face time will be allowed only if the filter in application and filter overrides is set to learn

b)

apple face time will be allowed, based on the apple filter configuration

c)

apple face time will be allowed, based on the categories configuration

d)

apple face time will be allowed, based on the excessive-bandwidth filter configuration

12.

a network administrato is troubleshooting an IPsec tunnel between two fortigate devices. the administrator has determined that phase 1 faild to come up. the administrator has also re-entered the pre-shared key on both.......................choose two.28

a)

on remote fortigate, set port2 as interface,

b)

on both fortigate devices, set dead peer detection to on demand

c)

on HQ-fortigate, set IKE mode to main (ID protection)

d)

on HQ-fortigate, disable diffie-helman group2

13.

a network administrator is troubleshooting an IPsec tunnel between two fortigate devices. the administrator has determined that phase 1 status is up, but phase 2 fails to come up. based on the phase 2 configuration shown in the exhibit, what configuration change will bring phase 2 up? 32

a)

on HQ-fortigate, enable auto-negotiate

b)

on remote-fortigate, set seconds to 43200

c)

on HQ-fortigate, set encryption to AES256

d)

on HQ-fortigate, enable diffie-hellman group 2

14.

which two key configuration changes are neede on fortigate to meet the design requirements?choose two.35

a)

configure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel

b)

enable dead peer detection

c)

configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel

d)

enable auto-negotiate and autokey keep alive on the phase 2 configuration of both tunnels

15.

refer to the fortiguard connection debug output. based on the output shown in the exhibit, which two statement are correct?choose two.37

a)

there is at least one server that lost packet consecutively

b)

one server was contacted to retrieve the contract information

c)

fortigate is using default fortiguard communication settings

d)

a local fortimanager is one of the servers fortigate communicates with

16.

an administrator creates a new address object on the root fortigate(local-fortigate) in the security fabric. after synchronization, this object is not available on the downstream fortigate(ISFW) what must the administrator do to synchronize the address object?38

a)

change the csf setting on local-fortigate(root) to set fabric-object-unification default

b)

change the csf setting on ISFW (downstream) to set fabric-object-unification default

c)

change the csf setting on Local-fortigate (root) to set configuration-sync local

d)

change the csf setting on ISFW (downstream) to set configuration-sync local

17.

the exhibits show the firewall policies and the objects used in the firewall policies. the administrator is using the policy lookup feature and has entered the search criteria shown in the exhibit. which policy will be highlighted, based on the input criteria?40

a)

policies with ID 2 and 3

b)

policy with ID 5

c)

policy with ID 1

d)

policy with ID 4

18.

the exhibit shows the fortiguard category based filtersection of a corporate web filter profile. an administrator must block access to download.com, which belongs to the fireware and software downloads category. choose options? 41

a)

configure a separate firewall policy with action Deny an FQDN address object for *. download.com as destination address

b)

configure a static URL filter entry download.com with tupe and action set to wilcard and block, respectively

c)

configure a web override rating for download.com and select malicious websites as the subcategory

d)

set the freeware and software downloads category action to warning

19.

the exhibit shows the fortiguard category based filtersection of a corporate web filter profile. an administrator must block access to download.com, which belongs to the fireware and software downloads category. choose options? 41

a)

configure a separate firewall policy with action Deny an FQDN address object for *. download.com as destination address

b)

configure a static URL filter entry download.com with tupe and action set to wilcard and block, respectively

c)

configure a web override rating for download.com and select malicious websites as the subcategory

d)

set the freeware and software downloads category action to warning

20.

refer to the fortiguard connection debug output. based on the output shown in the exhibit, which two statement are correct?choose two.37

a)

there is at least one server that lost packet consecutively

b)

one server was contacted to retrieve the contract information

c)

fortigate is using default fortiguard communication settings

d)

a local fortimanager is one of the servers fortigate communicates with

21.

exhibit a shows a network diagram. exhibit b shows the firewall policy configuration and a VIP object configuration the WAN(port1) interface has IP adress 10.200.1.1/24 the lan (port3) interface has the ip address 10.0.1.254/24. hte administrator disable the web server firewall policy. which IP address will be used to source nat.........42

a)

10.200.1.10

b)

10.200.3.1

c)

10.200.1.1

d)

10.0.1.254

22.

the exhibit shows a diagram of a fortigate device connected to hte network and the firewall policy and IP pool configuration on the fortigate device. two pcs,pc1 and pc2, are connected behind fortigate and can access the internet successfully. however, when the administrator adds a third PC to the network(pc3)43

a)

configure another firewall policy that matches only the address of pc3 as source, and then place the policy on top of the list

b)

in the ip pool configuration set endip to 192.2.0.12

c)

in the firewall policy configuration, disable ippol

d)

configure 192.2.0.12/24 as the secondary IP address on port1

e)

in the IP pool configuration, set type to overload

23.

the exhibits show a firewall policy(exhibit A) and an antivirus profile (exhibit B) why is the user unable to receive a block replacement mesage when downloading an infected file for the first time?44

a)

the firewall policy performs a full content on the file

b)

the intrusion prevention security profile must be enabled when using flow-based inspection mode

c)

the volume of traffic being inspected is too high for this model of fortigate

d)

flow-based inspections is used, which resets the last packet to the user

24.

the exhibits contain a network interface configuration, firewall policies, and a CLI console configuration. how will the fortigate device handle user authentication for traffic that arrives on the LAN interface?45

a)

if the as a fall-through policy in place, users will not be prompted for authentication

b)

authentication is enforced only at a policy level, all users will be prompted for authentication

c)

all users will be prompted for authentication, users from the sales group can authenticate successfully with the correct credentials

d)

all users will be prompted for authentication, users from the HR group can authenticate successfully with the correct credentials

25.

exhibit A shows a topology for a fortigate HA cluster that performs proxy-based inspection on traffic. exhibit B shows the HA configuration and the partial output of the get system ha status command based on the exhibits, which two statement about the traffic passing throught the cluster are true? choose two.46

a)

the cluster can load balance ICMP connections to the secondary

b)

the traffic sourced from the client and destined to the server is sent to FGT-1

c)

for load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary

d)

for non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source

26.

exhibit A shows a topology for a fortigate HA cluster that performs proxy-based inspection on traffic. exhibit B shows the HA configuration and the partial output of the get system ha status command based on the exhibits, which two statement about the traffic passing throught the cluster are true? choose two.46

a)

the cluster can load balance ICMP connections to the secondary

b)

the traffic sourced from the client and destined to the server is sent to FGT-1

c)

for load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary

d)

for non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source

27.

the exhibit shows a diagram of a fortigate device connected to hte network and the firewall policy and IP pool configuration on the fortigate device. two pcs,pc1 and pc2, are connected behind fortigate and can access the internet successfully. however, when the administrator adds a third PC to the network(pc3)43

a)

configure another firewall policy that matches only the address of pc3 as source, and then place the policy on top of the list

b)

in the ip pool configuration set endip to 192.2.0.12

c)

in the firewall policy configuration, disable ippol

d)

configure 192.2.0.12/24 as the secondary IP address on port1

e)

in the IP pool configuration, set type to overload

28.

the exhibit shows a diagram of a fortigate device connected to the network and the firewall policy and IP pool configuration on the fortigate device. which two actions does fortigate take on internet traffic sourced from the subscribers? choose two47

a)

fortigate allocates port blocks on a first-come, first-server basis.

b)

fortigate allocates 128 port blocks per user

c)

fortigate generates a system event log for every port block allocation made per user

d)

fortigate allocates port blocks per user based on the configured range of internal IP addresses

29.

exhibit a shows a network diagram. exhibit b shows the firewall policy configuration and a VIP object configuration. the WAN (port1) interface has the IP address 10.200.1.1/24 the LAN (port3) interface has the IP address 10.0.1.254/24 if the host 10.200.3.1 sends a TCP SYN packet on port 10443 to 10.200.1.10, what will the source address..........63

a)

10.0.1.254,10.200.1.10, and 443, respectively

b)

10.200.3.1, 10.0.1.10, and 443, respectively

c)

10.0.1.254, 10.0.1.10, and 10443, respectively

d)

10.0.1.254, 10.0.1.10, and 443, respectively

30.

the exhibit shows a diagram of a fortigate device connected to the network and the firewall policy and IP pool configuration on the fortigate device. which two actions does fortigate take on internet traffic sourced from the subscribers? choose two47

a)

fortigate allocates port blocks on a first-come, firts-serverd basis

b)

fortigate allocates 128 port blocks per user

c)

fortigate generates a system event log for every port block allocation made per user

d)

fortigate allocates port blocks per user based on the configured range of internal IP addresses

31.

exhibit a shows a network diagram. exhibit b shows the firewall policy configuration and a VIP object configuration. the WAN (port1) interface has the IP address 10.200.1.1/24 the LAN (port3) interface has the IP address 10.0.1.254/24 if the host 10.200.3.1 sends a TCP SYN packet on port 10443 to 10.200.1.10, what will the source address..........63

a)

10.0.1.254,10.200.1.10, and 443, respectively

b)

10.200.3.1, 10.0.1.10, and 443, respectively

c)

10.0.1.254, 10.0.1.10, and 10443, respectively

d)

10.0.1.254, 10.0.1.10, and 443, respectively