wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Formulir tanpa judul

Total questions: 106

Worksheet time: 53mins

Name
Class
Date
1.
1. Review the IPsec phase 1 configuration in the exhibit; then answer the question below.
a)
The remote gateway address is 10.200.3.1
b)
The local IPsec interface address is 10.200.3.1
c)
The local gateway IP is the address assigned to port1
d)
The local gateway IP is 10.200.3.1
e)
2.
Which of the following items is NOT a packet characteristic matched by a firewall service object?
a)
ICMP type and code
b)
TCP/UDP source and destination ports
c)
IP protocol number
d)
TCP sequence number
3.
Which web filtering inspection mode inspects DNS traffic?
a)
DNS-based.
b)
FQDN-based.
c)
Flow-based.
d)
URL-based.
4.
You have created a new administrator account, and assign it the prof_admin profile. Which is false about that account's permissions?
a)
It cannot upgrade or downgrade firmware.
b)
t can create and assign administrator accounts to parts of its own VDOM.
c)
It can reset forgotten passwords for other administrator accounts such as "admin"
d)
It has a smaller permissions scope than accounts with the "super_admin" profile.
5.
2. Which of the following statements is correct regarding FortiGate interfaces and spanning tree protocol? (Choose Two)
a)
Only FortiGate switch interfaces Participate in spanning tree.
b)
All FortiGate interfaces in transparent mode VDOMs participate in spanning tree.
c)
All FortiGate interfaces in NAT/route mode VDOMs Participate in spanning tree.
d)
All FortiGate interfaces in transparent mode VDOMs may block or forward BPDUs.
6.
Which statements are correct properties of a partial mesh VPN deployment. (Choose two.)
a)
VPN tunnels interconnect between every single location.
b)
VPN tunnels are not configured between every single location.
c)
Some location may be reachable via a hub location.
d)
There are no hub locations in a partial mesh.
7.
Which statement best describes what SSL.root is?
a)
The name of the virtual network adapter required in each user's PC for SSL VPN Tunnel mode.
b)
The name of a virtual interface in the root VDOM where all the SSL VPN user traffic comes from.
c)
A Firewall Address object that contains the IP addresses assigned to SSL VPN users.
d)
The virtual interface in the root VDOM that the remote SSL VPN tunnels connect to.
8.
In a FSSO agentless polling mode solution, where must the collector agent be?
a)
In any Windows server
b)
In any of the AD domain controller
c)
In the master AD domain controller
d)
The FortiGate device polls the AD domain controllers
9.
How many packets are interchanged between both IPSec ends during the negotiation of a main-mode phase 1?
a)
5
b)
3
c)
2
d)
6
10.
You have configured the DHCP server on a FortiGate's port1 interface (or internal, depending on the model) to offer IPs in a range of 192.168.1.65-192.168.1.253. When the first host sends a DHCP request, what IP will the DHCP offer?
a)
192.168.1.99
b)
192.168.1.253
c)
192.168.1.65
d)
192.168.1.66
11.
Which of the following IPsec configuration modes can be used when the FortiGate is running in NAT mode?
a)
Policy-based VPN only
b)
Both policy-based and route-based VPN.
c)
Route-based VPN only
d)
IPSec VPNs are not supported when the FortiGate is running in NAT mode.
12.
Which of the following statements are correct differences between NAT/route and transparent mode? (Choose two.)
a)
In transparent mode, interfaces do not have IP addresses
b)
Firewall polices are only used in NAT/ route mode.
c)
Static routers are only used in NAT/route mode.
d)
. Only transparent mode permits inline traffic inspection at layer 2.
13.
Which type of conserve mode writes a log message immediately, rather than when the device exits conserve mode?
a)
Kernel
b)
Proxy
c)
System
d)
Device
14.
Which of the following are operating mode supported in FortiGate devices? (Choose two)
a)
Proxy
b)
Transparent
c)
NAT/route
d)
Offline inspection
15.
What methods can be used to access the FortiGate CLI? (Choose two.)
a)
Using SNMP.
b)
A direct connection to the serial console port.
c)
Using the CLI console widget in the GUI.
d)
Using RCP.
16.
Of the following information, what can be recorded by a Data Leak Prevention sensor configured to do a summary archiving? (Choose three.)
a)
Visited URL (for the case of HTTP traffic)
b)
Sender email address (for the case of SMTP traffic)
c)
Recipient email address (for the case of SMTP traffic)
d)
Attached file (for the case of SMTP traffic)
e)
Email body (for the case of SMTP traffic)
17.
NEW QUESTION 138 Which of the following statements are correct regarding logging to memory on a FortiGate unit?
a)
When the system has reached its capacity for log messages, the FortiGate unit will stop logging to memory.
b)
When the system has reached its capacity for log messages, the FortiGate unit overwrites the oldest messages.
c)
If the FortiGate unit is reset or loses power, log entries captured to memory will be lost.
d)
None of the above
18.
Which statement is one disadvantage of using FSSO NetAPI polling mode over FSSO Security Event Log (WinSecLog) polling mode?
a)
It requires a DC agent installed in some of the Windows DC.
b)
It runs slower.
c)
It might miss some logon events.
d)
It requires access to a DNS server for workstation name resolution.
19.
Which of the following statements are correct about NTLM authentication? (Choose three)
a)
NTLM negotiation starts between the FortiGate device and the user's browser.
b)
It must be supported by the user's browser.
c)
It must be supported by the domain controllers
d)
. It does not require a collector agent.
20.
Which of the following correctly describes the cause for the dropped packets?
a)
The forward policy check.
b)
The reserve path forwarding check
c)
The subnet 172.20.169.0/24 is NOT in the Ottawa FortiGate's routing table.
d)
The destination workstation 172.20.169.2 does NOT have the subnet 172.20.168.0/24 in its routing table.
21.
Which UTM feature sends a UDP query to FortiGuard servers each time FortiGate scans a packet (unless the response is locally cached)
a)
Antivirus
b)
VPN
c)
IPS
d)
Web Filtering
22.
Bob wants to send Alice a file that is encrypted using public key cryptography. Which of the following statements is correct regarding the use of public key cryptography in this scenario?
a)
Bob will use his private key to encrypt the file and Alice will use her private key to decrypt the file.
b)
Bob will use his public key to encrypt the file and Alice will use Bob’s private key to decrypt the file.
c)
. Bob will use Alice’s public key to encrypt the file and Alice will use her private key to decrypt the file.
d)
. Bob will use his public key to encrypt the file and Alice will use her private key to decrypt the file.
23.
What is the default criteria for selecting the HA master unit in a HA cluster?
a)
. port monitor, priority, uptime, serial number
b)
Port monitor, uptime, priority, serial number
c)
Priority, uptime, port monitor, serial number
d)
uptime, priority, port monitor, serial number
24.
Which statements are true regarding IPv6 anycast addresses? (Choose two.)
a)
Multiple interfaces can share the same anycast address.
b)
They are allocated from the multicast address space
c)
Different nodes cannot share the same anycast address.
d)
An anycast packet is routed to the nearest interface.
25.
What are two requirements for DC-agent mode FSSO to work properly in a Windows AD environment? (Choose two.)
a)
DNS server must properly resolve all workstation names
b)
The remote registry service must be running in all workstations
c)
The collector agent must be installed in one of the Windows domain controllers
d)
A same user cannot be logged in into two different workstations at the same time
26.
A FortiGate is configured with three virtual domains (VDOMs). Which of the following statements is correct regarding multiple VDOMs
a)
The FortiGate must be a model 1000 or above to support multiple VDOMs
b)
A license has to be purchased and applied to the FortiGate before VDOM mode could be enabled.
c)
Changing the operational mode of a VDOM requires a reboot of the FortiGate
d)
The FortiGate supports any combination of VDOMs in NAT/Route and transparent modes.
27.
Which antivirus and attack definition update options are supported by FortiGate units? (Choose two.
a)
Manual update by downloading the signatures from the support site.
b)
FortiGuard pull updates.
c)
Push updates from a FortiAnalyzer
d)
execute fortiguard-AV-AS command from the CLI
28.
Caching improves performance by reducing FortiGate unit requests to the FortiGuard server. Which of the following statements are correct regarding the caching of FortiGuard responses
a)
Caching is available for web filtering, antispam, and IPS requests.
b)
The cache uses a small portion of the FortiGate system memory
c)
When the cache is full, the least recently used IP address or URL is deleted from the cache
d)
An administrator can configure the number of seconds to store information in the cache before the FortiGate unit contacts the FortiGuard server again
e)
The size of the cache will increase to accommodate any number of cached queries.
29.
Which of the following statements are true about Man-in-the-middle SSL Content Inspection? (Choose three.)
a)
The FortiGate device “re-signs” all the certificates coming from the HTTPS servers
b)
The FortiGate device acts as a sub-CA
c)
The local service certificate of the web server must be installed in the FortiGate device
d)
The FortiGate device does man-in-the-middle inspection.
e)
The required SSL Proxy certificate must first be requested to a public certificate authority (CA).
30.
What is the correct behavior when the email attachment is detected as a virus by the FortiGate antivirus engine?
a)
The FortiGate unit will remove the infected file and deliver the email with a replacement message to alert the recipient that the original attachment was infected.
b)
The FortiGate unit will reject the infected email and the sender will receive a failed delivery message.
c)
The FortiGate unit will remove the infected file and add a replacement messag
d)
. Both sender and recipient are notified that the infected file has been removed.
e)
The FortiGate unit will reject the infected email and notify the sender.
31.
In the debug command output shown in the exhibit, which of the following best described the MAC address 00:09:0f:69:03:7e ?
a)
. It is one of the secondary MAC addresses of the port1 interface.
b)
It is the primary MAC address of the port interface.
c)
It is the MAC address of another network devices located in the same LAN segment as the FortiGate unit's port1 interface
d)
It is the HA virtual MAC address
32.
What are required to be the same for two FortiGate units to form an HA cluster? (Choose two)
a)
Firmware
b)
Model
c)
Hostname.
d)
System time zone.
33.
What are the ways FortiGate can monitor logs? (Choose three.)
a)
Alert Emails
b)
SNMP
c)
Alert Message Console
d)
MIB
e)
SMS
34.
What is longest length of time allowed on a FortiGate device for the virus scan to complete
a)
20 seconds
b)
30 seconds
c)
45 seconds
d)
10 seconds
35.
Which of the following statements correctly describes the static routing configuration provided above?
a)
The FortiGate evenly shares the traffic to 172.20.168.0/24 through both routes.
b)
The FortiGate shares the traffic to 172.20.168.0/24 through both routes, but the port2 route will carry approximately twice as much of the traffic
c)
The FortiGate sends all the traffic to 172.20.168.0/24 through port1
d)
Only the route that is using port1 will show up in the routing table.
36.
A FortiGate unit operating in NAT/route mode and configured with two sub-interface on the same physical interface. Which of the following statement is correct regarding the VLAN IDs in this scenario?
a)
The two VLAN sub-interfaces can have the same VLAN IDs only if they have IP addresses in different subnets.
b)
The two VLAN sub-interfaces must have different VLAN IDs.
c)
The two VLAN sub-interfaces can have VLAN ID only if they belong to different VDOMs
d)
The two VLAN sub-interfaces can have the same VLAN if they are connected to different L2 IEEE 802.1Q complaint switches.
37.
How is traffic routed onto an SSL VPN tunnel from the FortiGate unit side?
a)
A static route must be configured by the administrator using the ssl.root interface as the outgoing interface
b)
Assignment of an IP address to the client causes a host route to be added to the FortiGate unit's kernel routing table.
c)
A route back to the SSLVPN IP pool is automatically created on the FortiGate unit.
d)
The FortiGate unit adds a route based upon the destination address in the SSL VPN firewall policy.
38.
Which of the following settings can be configured per VDOM? (Choose three)
a)
Operating mode (NAT/route or transparent)
b)
Static routes
c)
. Hostname
d)
System time
e)
Firewall Policies
39.
The workstation, 172.16.1.1/24, connects to port2 of the FortiGate device, and the ISP router, 172.16.1.2, connects to port1. Without changing IP addressing, which configuration changes are required to properly forward users traffic to the Internet? (Choose two)
a)
At least one firewall policy from port2 to port1 to allow outgoing traffic
b)
A default route configured in the FortiGuard devices pointing to the ISP's router.
c)
Static or dynamic IP addresses in both ForitGate interfaces port1 and port2.
d)
The FortiGate devices configured in transparent mode.
40.
Which is NOT true about source matching with firewall policies?
a)
. A source address object must be selected in the firewall policy.
b)
A source user/group may be selected in the firewall policy
c)
A source device may be defined in the firewall policy.
d)
A source interface must be selected in the firewall policy
e)
. A source user/group and device must be specified in the firewall policy.
41.
Files reported as "suspicious" were subject to which Antivirus check"?
a)
Grayware
b)
Virus
c)
Sandbox
d)
Heuristic
42.
Which statements are correct for port pairing and forwarding domains? (Choose two.)
a)
They both create separate broadcast domains
b)
Port Pairing works only for physical interfaces
c)
Forwarding Domain only applies to virtual interfaces
d)
They may contain physical and/or virtual interfaces.
43.
Which profile could IPS engine use on an interface that is in sniffer mode? (Choose three)
a)
Antivirus (flow based
b)
Web filtering (PROXY BASED)
c)
Intrusion Protection
d)
Application Control
e)
Endpoint control
44.
Which statements are correct regarding virtual domains (VDOMs)? (Choose two)
a)
VDOMs divide a single FortiGate unit into two or more virtual units that each have dedicated memory and CPUs.
b)
A management VDOM handles SNMP, logging, alert email and FDN-based updates.
c)
VDOMs share firmware versions, as well as antivirus and IPS databases.
d)
Different time zones can be configured in each VDOM
45.
Which action does the FortiGate take when link health monitor times out?
a)
All routes to the destination subnet configured in the link health monitor are removed from the routing table
b)
The distance values of all routes using interface configured in the link health monitor are increased.
c)
The priority values of all routes using configured in the link health monitor are increased.
d)
. All routes using the next-hop gateway configured in the link health monitor are removed from the routing table.
46.
The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below. Based on the firewall configuration illustrated in the exhibit, which statement is correct?
a)
A user that has not authenticated can access the Internet using any protocol that does not trigger an authentication challenge.
b)
A user that has not authenticated can access the Internet using any protocol except HTTP, HTTPS, Telnet, and FTP.
c)
A user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they can access all Internet services.
d)
DNS Internet access is always allowed, even for users that have not authenticated.
47.
Which of the following statements is true regarding a FortiGate device operating in transparent mode? (Choose three.)
a)
It acts as a layer 2 bridge
b)
It acts as a layer 3 route
c)
It forwards frames using the destination MAC address.
d)
It forwards packets using the destination IP address
e)
it can perform content inspection (antivirus, web filtering, etc)
48.
Which is true about incoming and outgoing interfaces in firewall policies?
a)
A physical interface may not be used.
b)
A zone may not be used
c)
Multiple interfaces may not be used for both incoming and outgoing.
d)
Source and destination interfaces are mandatory
49.
Given the information provided in the exhibits, which of the following statements are correct? (Choose two.)
a)
STUDENT is likely to be the master device.
b)
Session-pickup is likely to be enabled.
c)
. The cluster mode is active-passive.
d)
There is not enough information to determine the cluster mode.
50.
For data leak prevention, which statement describes the difference between the block and quarantine actions?
a)
A block action prevents the transactio
b)
A quarantine action blocks all future transactions, regardless of the protocol.
c)
A quarantine action archives the data.
d)
A block action has a finite duratio
e)
A quarantine action must be removed by an administrator.
51.
You are creating a custom signature. Which has incorrect syntax?
a)
. F-SBID(--attack_id 1842,--name "Ping.Death";--protocol icmp; --data_size>32000;)
b)
F-SBID(--name "Block.SMTP.VRFY.CMD";--pattern "vrfy";-- service SMTP; --no_case;-- context header;)
c)
F-SBID(--name "Ping.Death";--protocol icmp;--data_size>32000;)
d)
F-SBID(--name "Block".HTTP.POST"; --protocol tcp;-- service HTTP;-- flow from_client;--pattern "POST"; -- context uri;--within 5,context;)
52.
What is not true of configuring disclaimers on the FortiGate?
a)
Disclaimers can be used in conjunction with captive portal.
b)
Disclaimers appear before users authenticate.
c)
Disclaimers can be bypassed through security exemption lists.
d)
Disclaimers must be accepted in order to continue to the authentication login or originally intended destination.
53.
Which statements are true regarding traffic shaping that is applied in an application sensor, and associated with the firewall policy? (Choose two.)
a)
Shared traffic shaping cannot be used.
b)
Only traffic matching the application control signature is shaped
c)
Can limit the bandwidth usage of heavy traffic applications.
d)
Per-IP traffic shaping cannot be used.
54.
When an administrator attempts to manage FortiGate from an IP address that is not a trusted host, what happens?
a)
. FortiGate will still subject that person's traffic to firewall policies; it will not bypass them.
b)
FortiGate will drop the packets and not respond.
c)
. FortiGate responds with a block message, indicating that it will not allow that person to log in
d)
FortiGate responds only if the administrator uses a secure protoco
e)
Otherwise, it does not respond
55.
When configuring LDAP on the FortiGate as a remote database for users, what is not a part of the configuration?
a)
The name of the attribute that identifies each user (Common Name Identifier).
b)
The user account or group element names (user DN).
c)
The server secret to allow for remote queries (Primary server secret)
d)
The credentials for an LDAP administrator (password).
56.
Which of the following statements best describes what a Public Certificate Authority (CA) is?
a)
A service that provides a digital certificate each time a user is authenticating
b)
An entity that certifies that the information contained in a digital certificate is valid and true.
c)
. The FortiGate process in charge of generating digital certificates on the fly for SSL inspection purposes
d)
A service that validates digital certificates for certificate-based authentication purposes
57.
In a Crash log, what does a status of 0 indicate?
a)
Abnormal termination of a process
b)
. A process closed for any reason
c)
Scanunitd process crashed
d)
Normal shutdown with no abnormalities
e)
DHCP process crashed
58.
Regarding tunnel-mode SSL VPN, which three statements are correct? (Choose three.)
a)
Split tunneling is supported.
b)
It requires the installation of a VPN client.
c)
It requires the use of an Internet browser.
d)
. It does not support traffic from third-party network applications.
e)
Opsi 5
59.
A FortiGate unit has multiple VDOMs in NAT/route mode with multiple VLAN interfaces in each VDOM. Which of the following statements is correct regarding the IP addresses assigned to each VLAN interface?
a)
. Different VLANs can share the same IP address as long as they have different VLAN IDs.
b)
. Different VLANs can share the same IP address as long as they are in different physical interface.
c)
Different VLANs can share the same IP address as long as they are in different VDOMs
d)
Different VLANs can never share the same IP addresses
60.
What attributes are always included in a log header? (Choose three.)
a)
level
b)
time
c)
subtype
d)
policyid
e)
user
61.
Which of the following are possible actions for FortiGuard web category filtering? (Choose three.)
a)
Allow
b)
Block
c)
Exempt
d)
Warning
e)
Shape
62.
Which best describes the mechanism of a TCP SYN flood?
a)
The attackers keeps open many connections with slow data transmission so that other clients cannot start new connections.
b)
The attackers sends a packets designed to sync with the FortiGate
c)
The attacker sends a specially crafted malformed packet, intended to crash the target by exploiting its parser.
d)
the attacker starts many connections, but never acknowledges to fully form them.
63.
Which changes to IPS will reduce resource usage and improve performance? (Choose three)
a)
In custom signature, remove unnecessary keywords to reduce how far into the signature tree that FortiGate must compare in order to determine whether the
b)
In IPS sensors, disable signatures and rate based statistics (anomaly detection) for protocols, applications and traffic directions that are not relevant.
c)
in IPS filters, switch from 'Advanced' to 'Basic' to apply only the most essential signatures.
d)
In firewall policies where IPS is not needed, disable IPS.
e)
In firewall policies where IPS is used, enable session start logs.
64.
Which of the following items does NOT support the Logging feature?
a)
File Filter
b)
Application control
c)
Session timeouts
d)
Administrator activities
e)
Web URL filtering
65.
Which statement best describes the objective of the SYN proxy feature available in SP processors?
a)
Accelerate the TCP 3-way handshake
b)
Collect statistics regarding traffic sessions
c)
Analyze the SYN packet to decide if the new session can be offloaded to the SP processor
d)
Protect against SYN flood attacks.
66.
Which of the following are possible actions for static URL filtering? (Choose three.)
a)
Allow
b)
Block
c)
Exempt
d)
Warning
e)
Shape
67.
Which statement describes the green status indicators that appear next to the different FortiGuard Distribution Network services as illustrated in the exhibit?
a)
They indicate that the FortiGate has the latest updates available from the FortiGuard Distribution Network.
b)
They indicate that updates are available and should be downloaded from the FortiGuard Distribution Network to the FortiGate unit.
c)
They indicate that the FortiGate is in the process of downloading updates from the FortiGuard Distribution Network.
d)
They indicate that the FortiGate is able to connect to the FortiGuard Distribution Network.
68.
Which of the following statements are correct concerning the FortiGate session life support protocol? (Choose two)
a)
By default, UDP sessions are not synchronized.
b)
. Up to four FortiGate devices in standalone mode are supported.
c)
only the master unit handles the traffic.
d)
Allows per-VDOM session synchronization.
69.
NEW QUESTION 87 Examine the static route configuration shown below; then answer the question following it. config router static edit 1 set dst 172.20.1.0 255.255.255.0 set device port1 set gateway 172.11.12.1 set distance 10 set weight 5 next edit 2 set dst 172.20.1.0 255.255.255.0 set blackhole enable set distance 5 set weight 10 next end Which of the following statements correctly describes the static routing configuration provided? (Choose two.)
a)
All traffic to 172.20.1.0/24 is dropped by the FortiGate
b)
As long as port1 is up, all traffic to 172.20.1.0/24 is routed by the static route number 1. if the interface port1 is down, the traffic is routed using the blackhole
c)
The FortiGate unit does NOT create a session entry in the session table when the traffic is being routed by the blackhole route
d)
The FortiGate unit creates a session entry in the session table when the traffic is being routed by the blackhole route.
70.
An administrator configures a FortiGate unit in Transparent mode on the 192.168.11.0 subnet. Automatic Discovery is enabled to detect any available FortiAnalyzers on the network. Which of the following FortiAnalyzers will be detected?
a)
192.168.11.100
b)
192.168.11.251
c)
192.168.10.100
d)
192.168.10.251
71.
Which two web filtering inspection modes inspect the full URL? (Choose two.)
a)
DNS-based
b)
Proxy-based
c)
Flow-based
d)
URL-based
72.
Which network protocols are supported for administrative access to a FortiGate unit? (Choose three.)
a)
SMTP
b)
WINS
c)
HTTP
d)
Telnet
e)
Opsi 5
73.
Which statement best describes what a Fortinet System on a Chip (SoC) is?
a)
Low-power chip that provides general purpose processing power
b)
Chip that combines general purpose processing power with Fortinet’s custom ASIC technology
c)
Light-version chip (with fewer features) of an SP processor
d)
. Light-version chip (with fewer features) of a CP processor
74.
Which statements are correct regarding application control? (Choose two.)
a)
It is based on the IPS engine.
b)
It is based on the AV engine.
c)
. It can be applied to SSL encrypted traffic.
d)
It cannot be applied to SSL encrypted traffic It cannot be applied to SSL encrypted traffic
75.
Which action does the FortiGate take when link health monitor times out?
a)
All routes to the destination subnet configured in the link health monitor are removed from the routing table
b)
the distance values of all routes using interface configured in the link health monitor are increased.
c)
The priority values of all routes using configured in the link health monitor are increased.
d)
All routes using the next-hop gateway configured in the link health monitor are removed from the routing table.
76.
An Internet browser is using the WPAD DNS method to discover the PAC files URL. The DNS server replies to the browsers request with the IP address 10.100.1.10. Which URL will the browser use to download the PAC file?
a)
http://10.100.1.10/proxy.pac
b)
https://10.100.1.10/
c)
http://10.100.1.10/wpad.dat
d)
https://10.100.1.10/proxy.pac
77.
What is the default criteria for selecting the HA master unit in a HA cluster?
a)
port monitor, priority, uptime, serial number
b)
Port monitor, uptime, priority, serial number
c)
Priority, uptime, port monitor, serial number
d)
uptime, priority, port monitor, serial number
78.
Which changes to IPS will reduce resource usage and improve performance? (Choose three)
a)
In custom signature, remove unnecessary keywords to reduce how far into the signature tree that FortiGate must compare in order to determine whether the packet matches.
b)
In IPS sensors, disable signatures and rate based statistics (anomaly detection) for protocols, applications and traffic directions that are not relevant.
c)
In IPS filters, switch from 'Advanced' to 'Basic' to apply only the most essential signatures.
d)
In firewall policies where IPS is not needed, disable IPS.
e)
In firewall policies where IPS is used, enable session start logs.
79.
Which statements are true regarding the use of a PAC file to configure the web proxy settings in an Internet browser? (Choose two.)
a)
Only one proxy is supported.
b)
Can be manually imported to the browser.
c)
The browser can automatically download it from a web server.
d)
Can include a list of destination IP subnets where the browser can connect directly to without using a proxy.
80.
Which commands are appropriate for investigating high CPU? (Choose two.)
a)
diag sys top
b)
diag hardware sysinfo mem
c)
diag debug flow
d)
get system performance status
81.
Which of the following statements describes the objectives of the gratuitous ARP packets sent by an HA cluster?
a)
To synchronize the ARp tables in all the FortiGate Unis that are part of the HA cluster.
b)
To notify the network switches that a new HA master unit has been elected.
c)
To notify the master unit that the slave devices are still up and alive.
d)
To notify the master unit about the physical MAC addresses of the slave units.
82.
Which are outputs for the command ‘diagnose hardware deviceinfo nic’? (Choose two.)
a)
ARP cache
b)
Physical MAC address
c)
Errors and collisions
d)
Listening TCP ports
83.
Which of the following statements are correct regarding SSL VPN Web-only mode? (Choose two.)
a)
It can only be used to connect to web services.
b)
IP traffic is encapsulated over HTTPS.
c)
Access to internal network resources is possible from the SSL VPN portal.
d)
The standalone FortiClient SSL VPN client CANNOT be used to establish a Web-only SSL VPN.
e)
It is not possible to connect to SSH servers through the VPN.
84.
How many packets are interchanged between both IPSec ends during the negotiation of a main-mode phase 1?
a)
5
b)
3
c)
2
d)
6
85.
Which statements are correct regarding this configuration? (Choose two.)
a)
The Phase 2 will re-key even if there is no traffic.
b)
There will be a DH exchange for each re-key
c)
The sequence number of ESP packets received from the peer will not be checked.
d)
Quick mode selectors will default to those used in the firewall policy.
86.
Which statement best describes what a Fortinet System on a Chip (SoC) is?
a)
Low-power chip that provides general purpose processing power
b)
Chip that combines general purpose processing power with Fortinets custom ASIC technology
c)
Light-version chip (with fewer features) of an SP processor
d)
Light-version chip (with fewer features) of a CP processor
87.
What types of troubleshooting can you do when uploading firmware? (Choose two.)
a)
Investigate corrupted firmware
b)
Investigate current runtime state
c)
Investigate damaged hardware
d)
Investigate configuration history
88.
Which statements are true regarding the session above? (Choose two.)
a)
Session Time-To-Live (TTL) was configured to 9 seconds.
b)
FortiGate is doing NAT of both the source and destination IP address on all packets coming from the 192.168.1.110 address.
c)
The IP address 192.168.1.110 is being translated to 172.17.87.16.
d)
The FortiGate is not translating the TCP port numbers of the packets in this session.
89.
Which statement is correct concerning an IPsec VPN with the remote gateway setting configured as 'Dynamic DNS'?
a)
The FortiGate will accept IPsec VPN connection from any IP address.
b)
The FQDN resolution of the local FortiGate IP address where the VPN is terminated must be provided by a dynamic DNS provider.
c)
The FortiGate will Accept IPsec VPN connections only from IP addresses included on a dynamic DNS access list.
d)
The remote gateway IP address can change dynamically.
90.
Which portion of the configuration does an administrator specify the type of IPsec configuration (either policy-based or route-based)?
a)
Under the IPsec VPN global settings
b)
Under the phase 2 settings.
c)
Under the phase 1 settings.
d)
Under the firewall policy settings.
91.
Which statements are true regarding the factory default configuration? (Choose three.)
a)
The default web filtering profile is applied to the first firewall policy.
b)
The 'Port1' or 'Internal' interface has the IP address 192.168.1.99.
c)
The implicit firewall policy action is ACCEPT.
d)
The 'Port1' or 'Internal' interface has a DHCP server set up and enabled (on device models that support DHCP servers).
e)
Default login uses the username: admin (all lowercase) and no password
92.
Which does FortiToken use as input when generating a token code? (Choose two.)
a)
User password
b)
Time
c)
User name
d)
Seed
93.
What is valid reason for using session based authentication instead of IP based authentication in a FortiGate web proxy solution?
a)
Users are required to manually enter their credentials each time they connect to a different web site.
b)
Proxy users are authenticated via FSSO.
c)
Opsi There are multiple users sharing the same IP address.3
d)
Proxy users are authenticated via RADIUS.
94.
How do application control signatures update on a FortiGate device?
a)
Through FortiGuard updates.
b)
Upgrade the FortiOS firmware to a newer release.
c)
By running the Application Control auto-learning feature.
d)
Signatures are hard coded to the device and cannot be updated.
95.
Which best describes the authentication timeout?
a)
How long FortiGate waits for the user to enter his or her credentials.
b)
How long a user is allowed to send and receive traffic before he or she must authenticate again.
c)
How long an authenticated user can be idle (without sending traffic) before they must authenticate again.
d)
How long a user-authenticated session can exist without having to authenticate again.
96.
In this scenario. The FortiGate unit in Ottawa has the following routing table: s*0.0.0.0/0 [10/0] via 172.20.170.254, port2 c172.20.167.0/24 is directly connected, port1 c172.20.170.0/24 is directly connected, port2 Sniffer tests show that packets sent from the source IP address 170.20.168.2 to the destination IP address 172.20.169.2 are being dropped by the FortiGate located in Ottawa. Which of the following correctly describes the cause for the dropped packets?
a)
The forward policy check.
b)
The reserve path forwarding check.
c)
The subnet 172.20.169.0/24 is NOT in the Ottawa FortiGate's routing table.
d)
The destination workstation 172.20.169.2 does NOT have the subnet 172.20.168.0/24 in its routing table.
97.
Which statements are true regarding traffic shaping that is applied in an application sensor, and associated with the firewall policy? (Choose two.)
a)
Shared traffic shaping cannot be used.
b)
Only traffic matching the application control signature is shaped.
c)
Can limit the bandwidth usage of heavy traffic applications.
d)
Per-IP traffic shaping cannot be used.
98.
Files reported as "suspicious" were subject to which Antivirus check"?
a)
Grayware
b)
Virus
c)
Sandbox
d)
Heuristic
99.
To which remote device can the FortiGate send logs? (Choose three.)
a)
Syslog
b)
FortiAnalyzer
c)
Hard drive
d)
Memory
100.
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
a)
get system status
b)
diagnose sys top
c)
get system performance status
d)
get system arp
101.
Which policy will be highlighted, based on the input criteria?
a)
Policies with ID 2 and 3.
b)
Policy with ID 4.
c)
Policy with ID 5.
d)
Opsi 4
102.
Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
a)
The signature setting uses a custom rating threshold.
b)
Traffic matching the signature will be silently dropped and logged.
c)
The signature setting includes a group of other signatures.
d)
Traffic matching the signature will be allowed and logged.
103.
An administrator has configured a strict RPF check on FortiGate. Which statement is true about the strict RPF check?
a)
Strict RPF checks the best route back to the source using the incoming interface
b)
Strict RPF checks only for the existence of at least one active route back to the source using the incoming interface.
c)
The strict RPF check is run on the first sent and reply packet of any new session
d)
Strict RPF allows packets back to sources with all active routes.
104.
What is a reason for triggering IPS fail open?
a)
The IPS engine cannot decode a packet.
b)
The IPS socket buffer is full and the IPS engine cannot process additional packets.
c)
The administrator enabled NTurbo acceleration.
d)
The IPS engine is upgraded.
105.
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL Inspection? (Choose two.)
a)
The issuer must be a public C
b)
The common name on the subject field must use a wildcard name.
c)
The CA extension must be set to TRUE.
d)
The keyUsage extension must be set to keyCertSign
106.
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. * All traffic must be routed through the primary tunnel when both tunnels are up * The secondary tunnel must be used only if the primary tunnel goes down * In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two,)
a)
Enable Dead Peer Detection.
b)
Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel.
c)
Configure a high distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel.
d)
Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels.