WorksheetsSonicwall SNSA OS 7
Total questions: 108
Worksheet time: 1hrs 8mins
Which of the following are included in the output of a network monitor?
(select all that apply)
Probe Type
Interface
Probe Target
IP Version
Packet Type
What type of Intermediate traffic is monitored by the packet monitor?
(Select all that apply)
Multicast packets that are replicated
Encrypted packets
IP Helper-generated packets
Exported packets
Expired Packets
What export formats are available for a snapshot of the Packet Monitor?
(Select all that apply_
Excel Chart
XML
HTML
Plain Text
Pcap
Which Packet Status types are indicated by the Packet Monitor?
(Select all that apply)
Imported
Dropped
Exported
Forwarded
Consumed
SonicWall Capture Client is a unified client platform that delivers multiple endpoint protection capabilities.
Ture
False
Capture Client facilitates multi-tenant management
True
False
Which feature of Endpoint Security protects against both file-based and file-less malware and delivers a 360-degree attack view with actionable intelligence relevant for investigations?
Content Filtering
Application Vulnerability Intelligence
Rollback
Continuous Behavioural Monitoring
Which of the following are available in with the BASIC Capture Client license?
(Select all that apply)
Rollback capability
Windows Server Support
Integration with Capture ATP
Integration with Capture Security Center
Role-based access control
Application Vulnerability Intelligence helps catalog every application on each protected endpoint.
True
False
Policy inheritance refers to the ability of a policy at child scope to be automatically inherited from the policy of the parent scope.
True
False
Which Feature is used to ensure the firewall licenses are the same as in the respective Mysonicwall.com account?
Generate Security Services summary
Manual Upgrade
Enter Keyset
Synchronize
What options are used to pre-empt an administrator logged into the firewall?
(Select all that apply)
Both administrators can manage simultaneously
Log out
Drop into Non-Config mode
Change to read-only a-ccess
What are some of the key features of SonicWall Next-Gen firewalls?
(Select all that apply)
Network segmentation
Application intelligence and control
single-layer security system
Flexible deployment
Operational complexity
What are some of the key features of SonicOS 7 architecture?
(Select all that apply)
Simplified intergration
Operational Complexity
Easy, Zero touch deployment
Advanced protection against encrypted threats
TLS 1.3
Select two best practices that should be implemented before updating the firewall firmware.
Download a settings file lcoally
Import a settings file
Use the create backup option built into the firewall
Disable the could backup option
The Public Server guide assigns the server automatically to the zone to which its IP address belongs
Ture
False
When configuring a Site-to-Site policy, the Local Network option must match the Destination Network on the other side of the tunnel, in order to avoid tunnel negotiation errors or even a total failure
Ture
False
Which of the following is the default public server type?
Terminal Services Server
Mail Server
FTP Server
Web Server
What type of mapping does ARP enable?
IP Addresses to MAC Addresses
Does not enable any mapping
MAC Addresses to Domain Names
IP Addresses to Domain Names
Which firewall network setting allows the current state of the DHCP leases in the network to be periodically written to Flash?
Enable DHCP Server Persistence
Enable DHCP Conflict Detection
Which advanced network interface setting on the SonicWall NSv firewall allows initial packets or response packets to pass through other interfaces?
Enable Asymmetric Route Support
Enable Flow Reporting
Enable Multicast Support
Which of the following DDNS Providers are supported in SonicOS?
(Select all that apply)
dyn.com
freedns.afriad.org
np-ip.com
dns.he.net
The SonicOS NSv scheme of interface addressing working in conjunction with address objects, service objects, and network zones.
True
False
Who among the following can manage Guest Accounts and Sessions?
SSL-VPN Administrators
Zone Administrators
Content Filter Administrators
Guest Administrators
Which of the following are the default user groups to which a new user is automatically added in a SonicWall firewall?
(Select all that apply)
Everyone
Guest Services
All Users
Trusted Users
Which user authentication methods are available in a SonicWall NSv?
(Select all that apply)
Local User
TACACS
LDAP
CHAP
RADIUS
The Default Guest Profile cannot be deleted.
Ture
False
Static routes, by default, take precedence over VPN traffic
True
False
TOS routing applies to packets as they exit from the firewall.
True
False
Advanced Routing is enabled by default.
True
False
Which of the following variables are used to configure static routes to forward traffic?
(Select all that apply)
Zones
Interfaces
Services
Encryption Polices
Which protocols are supported by the Advanced Routing mode of SonicWall Nsv?
(Select all that apply)
EIGRP
RIP
OSPFv3
IS-IS
As a general practice, all inbound connections should be logged
True
False
Setting the Event Priority level lower than the Logging Level will cause those event to be filtered out from Event Logs.
True
False
If the Logging level filter is defined as Error, which of the following alert messages will also be displayed in the results?
(select all that apply)
Alert
Critical
Notice
Emergency
Warning
Which Log Settings option is used to create a predefined email notification with a defined subject in firewall log management?
Email Log Automation
Base Setup
Syslog
Name Resolution
The connection Count monitor periodically updates the outgoing and incoming connection rates for each interface?
True
False
What type of information is displayed on the Protocol Monitor?
(select all that apply)
TCP Rate
HTTPS Connection
IPv4 Rate
ARP Rate
Packet Rate
The real-time monitoring features of the NSv firewall rely on the flow-collection mechanisms to collect and display data.
True
False
What is the default timeout for a administrator
5 mins
10 mins
15 mins
20 mins
what is the default username and password for a SonicWall.
admin // password
admin // admin
Admin // Password
Admin // Admin
What are the default zones?
LAN, WAN, DMZ, VPN, SSLVPN, MULTICAST
LAN, WAN, DMZ, SSLVPN
LAN, WAN, VPN, MULTICAST
LAN, WAN, DMZ, SSLVPN
Select all types of trusted zones
Trused
Public
SSL VPN
Untrusted
Please select all interface types
Virtual
VPN
4to6
Physical
What are the Management options on a interface?
HTTPS
PING
SNMP
SSH
HTTP
You can manage a SonicWall via HTTP by default
Ture
False
Select all modes for WAN
DHCP
PPPOE
PPTP
DSL
Select all modes for WAN
L2TP
Tap
Wire
VDSL
Select all modes for LAN
Static
Tap
Wire
DHCP
Mirror
Please Select all Address Object Types
Host
Range
Network
FQDN
MAC
Select All service object Types
ICMP
IGMP
TCP
UDP
HTTPS
Select All service object Types
6over4
GRE
ESP
AH
Host
Select all NAT Policy Types
Inbound
Outbound
Loopback
4to6
6to4
Select all types of NAT policy's you can create in a SonicWall
IPv4
IPv6
64
6over4
Access rules happen before NAT
True
False
By the SonicWall creates a inbound deny rule
True
False
Select all BWM Violation Options
Deny
Drop
Ignore
Consume
From the setup wizard select the Wizards you are prompted with
Public server
VPN
SDWAN
NAT Policy
GC VPN
Ingress refers to incoming data
True
False
Egress refers to outgoing data
True
False
Where can you apply Bandwidth management?
Access Rule
Application Rule
Content Filter
Service Object
Interfaces
Select the protocols Gateway AV can protect from
HTTP
FTP
SMTP
POP3
TOR
Select the protocols Gateway AV can protect from
NetBIOS
TCP
BitTorrent
Select the recommended IPS settings
Detect ALL
Prevent All
Prevent High and Medium
Detect High and Medium
Prevent High
Select the recommended Anti-Spyware settings
Detect ALL
Prevent All
Prevent High and Medium
Detect High and Medium
Prevent High
What are the security services offered by a SonicWALL Firewall
GAV
IPS
Anti-Spyware
App Control
Geo-IP
Security services are enabled on new Zones by default
True
False
Select all Capture ATP Server Locations
Amsterdam
Franfurt
Miami
San Jose
Tokyo
Select file types accepted by capture ATP
Executables
Office 97-2003
Office
Archives
Select the maximum file size for capture ATP
10MB
20MB
50MB
100MB
30MB
Recommend GEO-IP settings
Block all unknown contires
Block Proxy traffic
Block European traffic
Block African Traffic
Block Russian Traffic
Select All VPN types supported on a SonicWall
Gateway-to-Gateway // Site-to-Site
Host-to-Gateway
Host-to-Host
Peer-to-Peer
Select the VPN Policy types on a sonic wall
Site-to-Site
Tunnel Interface
Peer-to-Peer
Select all VPN Authentication Methods
Manual Key
IKE Using Preshared Secret
IKE using 3rd Party Certificates
Auto Provisioning Server
Auto Provisioning Client
Select all VPN Exchange Types
Main Mode
Aggressive Mode
IKEv2 Mode
TOR
P2P
Select all available VPN IPSEC Phase 2 Protocol Types
ESP
AH
EPS
HA
None
Select the VPN Defaults
Exchange - IKEv2, DH - Group 2, Encryption - AES-128, Auth SHA1
Exchange - IKEv2, DH - Group 3, Encryption - AES-128, Auth SHA1
Exchange - IKEv2, DH - Group 2, Encryption - AES-256, Auth SHA1
Exchange - IKEv2, DH - Group 2, Encryption - AES-128, Auth SHA128
Exchange - IKEv2, DH - Group 3, Encryption - AES-128, Auth SHA1
Select the standard VPN Routes
Auto Added Access Rule, Default metric: 20, Hops: Standard Route, Multi-Path Route, SD-WAN Rule
Auto Added Access Rule, Default metric: 20, Hops: Standard Route, Multi-Path Route
Auto Added Access Rule, Default metric: 20, Hops: Standard Route, SD-WAN Rule
Auto Added Access Rule, Default metric: 10, Hops: Standard Route, Multi-Path Route, SD-WAN Rule
Auto Added Access Rule, Default metric: 20, Hops: Multi-Path Route, SD-WAN Rule
Select the best authentication method for over 1000 users
RDIUS
LDAP
TACACS+
Local users
Select the best authentication method for over AAA (Authentication, Authorization and Accounting)
RDIUS
LDAP
TACACS+
Local users
Select the required ports for LDAP
389
636
3268
3269
4433
Select the available Schema Types
Microsoft AD
User Defined
Samba SMB
OpenDirectory
Select the available Schema Types
Microsoft AD
Novell eDirectory
RFC2307 Network Information Service
OpenDirectory
RFC2798 InetOrgPerson
What is the SSL VPN Port
4433
4443
443
4333
4345
Select Virtual Office bookmark types
RDP (HTML5)
SSHv2
TELNET
VNC
SSH
Where should the DPI-SSL certificate be imported to
Trusted Root certification authorities
Enterprise Trust
Trusted Publishers
Personal
Local NonRemovable Certificates
Where do you enable DPI SSL
Globally
Zone
Policy
NAT Rules
Interface
Select the correct list of CFS actions
Allow, BWM, Block, Confirm, Passphrase
Allow, BWM, Confirm, Passphrase
Allow, Block, Confirm, Passphrase
Allow, BWM, Block, Confirm
Allow, BWM, Block, Passphrase
The Content filtering service works from the top of the policy list to the bottom
True
False
Select the items required to create a CFS policy
Profile Object
Action Object
Zone
Address Object
Interface
What port is used by the SonicWall SSO agent
2258
2259
2257
2256
What port is used by the SonicWall SSO Terminal service agent agent
2258
2259
2257
2256
What is the passphrase requirements for the SSO Agent?
Hexadecimal, 8 Character minimum and an even number of characters
Hexadecimal, 8 Character minimum
8 Character minimum and an even number of characters
Hexadecimal and an even number of characters
In descending order the SonicWALL log priories are Emergency, Alert, Critical, Error, Warning, Notice, Inform, Debug
Ture
False
What are the Default App Rule Actions
Block SMTP W-Mail Without Reply
Bypass Capture ATP
Bypass DPI
Bypass GAV
Ignore
What are the Default App Rule Actions
Bypass IPS
Bypass ANIT-SPYWARE
No Action
Packet Monitor
Reset/Drop
App Control takes precedence over App Rule
True
False
Types of Failover/Load Balancing Types
Basic Failover
Round Robin
Spill-Over
Ratio
Active / Active
What are the Failover Probe settings
Physical Monitoring only
Logical/Probe Monitoring Enabled
Physical Monitoring and Logical/Probe Monitoring Enabled
None Listed
What are the Failover Probe Setting criteria available
Probe succeeds when EITHER Main
Alternate target responds
Prove Succeeds when BOTH Main or Alternate target responds
Probe Succeeds when main target responds or Succeeds Always
What are the Failover probe types?
TCP
ICMP
UDP
What are the SDWAN probe types?
TCP
ICMP
UDP
What is the Default probe address
Responder.global.sonicwall.com
Google.com
8.8.8.8
1.1.1.1
MySonicWall.com
What are the SDWAN SLA Class Object settings?
Lowest Latency
Lowest Jitter
Lowest Packet Loss
Highest thoughput
To enable HA both SonicWALL's must be the exact same model
Ture
False
To enable HA both firewalls must have the matching firmware
Ture
False
When HA is enabled the Control Link is used for Heartbeat and Interface Changes
Ture
False
How many cloud backups can you keep per firmware version
1
2
3
4
5
