wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SonicWall Firewall Features Quiz

Total questions: 155

Worksheet time: 1hrs 23mins

Name
Class
Date
1.

Which of the following advanced threat protection features are enabled by SonicOS?

a)

Intrusion Detection System (IDS)

b)

Sandboxing

c)

Data Loss Prevention (DLP)

d)

SSL+SSH+TLS decryption and inspection

2.

How many auto-scheduled cloud configuration backups are supported per firmware version in a SonicWall firewall?

a)

1 per firmware

b)

2 per firmware

c)

3 per firmware

d)

Unlimited

3.

In SonicOS, which panel of the management interface is used to define password restrictions?

a)

System > Administration

b)

Manage > Appliance > Base Settings > Login Security

c)

Security > Authentication

d)

Users > Password Management

4.

Which of the following is a built-in firewall system schedule in SonicWall?

a)

Business Hours

b)

Work Hours

c)

Weekend Mode

d)

Night Shift

5.

Which setting, when enabled, requires a strong password to avoid potential security vulnerabilities?

a)

Enable SSH Management

b)

Allow HTTPS on this WAN interface

c)

Enable SNMP Monitoring

d)

Enable VPN Access

6.

The HTTP-based management option in SonicOS is disabled by default.

a)

True

b)

False

7.

SonicWall firewalls can interoperate with any X.509v3 certificates issued by third-party CA authorities.

a)

True

b)

False

8.

Which of the following is the default public server type in SonicWall?

a)

Web Server

b)

FTP Server

c)

Terminal Services Server

d)

Mail Server

9.

Which local network is selected by default in the firewall?

a)

LAN Subnets

b)

Firewall Subnets

c)

VPN Zones

d)

DMZ Subnets

10.

Which of the following network applications are available by default in the App Rule Guide to create policies?

a)

SMTP

b)

FTP File Server

c)

Web Access

d)

All of the above

11.

Which Advanced Interface setting allows initial packets or response packets to pass through other interfaces?

a)

Enable Asymmetric Route Support

b)

Packet Filtering

c)

Stateful Inspection

d)

NAT Passthrough

12.

What is the default IP version setting for sending or receiving DNS Proxy packets between the firewall and DNS servers?

a)

IPv6 to IPv4

b)

IPv4 to IPv6

c)

IPv4 to IPv4

d)

IPv6 to IPv6

13.

Which option is a messaging protocol used to build a cache of dynamic entries for IPv6 devices?

a)

Address Resolution Protocol (ARP)

b)

Neighbor Discovery

c)

Dynamic Host Configuration Protocol (DHCP)

d)

Internet Control Message Protocol (ICMP)

14.

Which MAC-IP Anti-Spoof network setting prevents the spoofing of packets by a bad device or unwanted ARP packets?

a)

ARP Filtering

b)

MAC Binding

c)

ARP Lock

d)

Anti-Spoofing Mode

15.

What type of information does the DHCP server help distribute to network clients?

a)

IP Addresses

b)

Gateway Addresses

c)

DNS Server Settings

d)

Radius Server Settings

16.

Which of the following DDNS providers are supported in SonicOS?

a)

changeIP.com

b)

dyn.com

c)

no-ip.net

d)

All of the above

17.

Which user authentication method provides centralized authentication and authorization?

a)

LDAP

b)

RADIUS

c)

Local Users

d)

TACACS+

18.

Which authentication method is recommended for a relatively smaller number of users?

a)

RADIUS

b)

SSO Agent

c)

Local Users

d)

Active Directory

19.

Which type of SSO method identifies users based on the workstation IP address?

a)

Kerberos

b)

LDAP Proxy

c)

SSO Agent

d)

RADIUS Accounting

20.

Which of the following types of privileges can an admin be assigned to?

a)

Full privileges (config or non-config)

b)

Read-Only Access

c)

Custom Role-Based Access

d)

All of the above

21.

What type of specific and advanced threat protection features are enabled by SonicOS?

a)

Intrusion Detection System (IDS)

b)

Sandboxing

c)

Data Loss Prevention (DLP)

d)

SSL + SSH + TLS decryption and inspection

22.

How many auto-scheduled cloud configuration backups are supported for each firmware version in the SonicWall firewall?

a)

1 per firmware

b)

2 per firmware

c)

3 per firmware

d)

Unlimited

23.

Which panel of the SonicOS management interface is used to define password restrictions?

a)

System > Administration

b)

Manage > Appliance > Base Settings > Login Security

c)

Security > Authentication

d)

Users > Password Management

24.

The HTTP-based management option in SonicOS is disabled by default.

a)

True

b)

False

25.

SonicWall firewalls can interoperate with any X.509v3 certificates issued by third-party CA authorities.

a)

True

b)

False

26.

Which of the following is a built-in firewall system schedule?

a)

Business Hours

b)

Work Hours

c)

Weekend Mode

d)

Night Shift

27.

Which setting, when enabled, requires a strong password to avoid potential security vulnerabilities?

a)

Enable SSH Management

b)

Allow HTTPS on this WAN interface

c)

Enable SNMP Monitoring

d)

Enable VPN Access

28.

What is the default public server type in SonicWall?

a)

Web Server

b)

FTP Server

c)

Terminal Services Server

d)

Mail Server

29.

Which local network is selected by default in the firewall?

a)

LAN Subnets

b)

Firewall Subnets

c)

VPN Zones

d)

DMZ Subnets

30.

Which of the following network applications are available by default in the App Rule Guide to create policies?

a)

SMTP

b)

FTP File Server

c)

Web Access

d)

All of the above

31.

Which Advanced Interface setting allows initial packets or response packets to pass through other interfaces?

a)

Asymmetric Routing

b)

Packet Filtering

c)

Stateful Inspection

d)

NAT Passthrough

32.

What is the default IP version setting for sending or receiving DNS Proxy packets between the firewall and DNS servers?

a)

IPv6 to IPv4

b)

IPv4 to IPv6

c)

IPv4 to IPv4

d)

IPv6 to IPv6

33.

Which option is a messaging protocol used to build a cache of dynamic entries for IPv6 devices?

a)

Address Resolution Protocol (ARP)

b)

Neighbor Discovery

c)

Dynamic Host Configuration Protocol (DHCP)

d)

Internet Control Message Protocol (ICMP)

34.

Which MAC-IP Anti-Spoof network setting prevents spoofing of egress packets by a bad device or unwanted ARP packets?

a)

ARP Filtering

b)

MAC Binding

c)

ARP Lock

d)

Anti-Spoofing Mode

35.

What type of information does the DHCP server help distribute to network clients?

a)

IP Addresses

b)

Gateway Addresses

c)

DNS Server Settings

d)

All of the above

36.

Which of the following DDNS providers are supported in SonicOS?

a)

changeIP.com

b)

dyn.com

c)

no-ip.net

d)

All of the above

37.

Which user authentication method provides centralized authentication and authorization?

a)

LDAP

b)

RADIUS

c)

Local Users

d)

TACACS+

38.

Which authentication method is recommended for a relatively smaller number of users?

a)

RADIUS

b)

SSO Agent

c)

Local Users

d)

Active Directory

39.

Which type of SSO method identifies users based on the workstation IP address?

a)

Kerberos

b)

LDAP Proxy

c)

SSO Agent

d)

RADIUS Accounting

40.

Which of the following types of privileges can an admin be assigned to?

a)

Full privileges (config or non-config)

b)

Read-Only Access

c)

Custom Role-Based Access

d)

All of the above

41.

The default guest profile cannot be deleted.

a)

True

b)

False

42.

Which setting is enabled to prioritize VPN traffic over static routes?

a)

Enable Route Precedence

b)

Allow VPN path to take precedence

c)

Static Route Priority

d)

VPN Traffic Control

43.

Which option is a common mechanism for preventing routing loops?

a)

OSPF Redistribution

b)

Route Injection

c)

Split Horizon

d)

BGP Peering

44.

Which feature is used to configure event log attributes globally, using flexible match conditions?

a)

Go to CONFIGURE Log (on the right)

b)

Global Logging Settings

c)

Log Event Manager

d)

Match-Based Logging

45.

Which feature, located in the left panel, provides information about the applied filters?

a)

Event Log Summary

b)

Filter Logic (bottom of the page)

c)

Filter Debug Panel

d)

Packet Inspection Log

46.

Which client CF event object is assigned a higher priority level?

a)

Client CF access without agent (CRITICAL)

b)

Client CF access with agent (CRITICAL)

c)

Client CF Generic

d)

Default CF Event

47.

Which logging feature is used to create a predefined email notification with a defined subject?

a)

Notification Rules

b)

Event Triggering

c)

Automation

d)

Alert Forwarding

48.

What are two probe methods that can be used for logical probes? (Select all that apply)

a)

UDP

b)

Ping

c)

TCP

d)

ICMP

49.

Which action object is used to throttle the traffic when a website from a category is accessed?

a)

Content Filtering

b)

Bandwidth Management (BWM)

c)

App Control

d)

DPI-SSL Inspection

50.

Which of the following Address Object types is selected by default in the firewall?

a)

Host

b)

Network

c)

Range

d)

Zone

51.

Which diagnostic utility on the SonicWall firewall allows you to look at the contents of IP packets traversing the firewall?

a)

Log Analyzer

b)

Packet Monitor

c)

Connection Tracker

d)

DPI Monitor

52.

Where is the real-time data on the Dashboard compiled and summarized from?

a)

Manage >> AppFlow Settings

b)

Reports >> Logs

c)

System >> Diagnostics

d)

Network >> Traffic Monitor

53.

What type of information is displayed on the Live Monitor panel? (Select all that apply)

a)

Applications

b)

Ingress/Egress Bandwidth

c)

Ingress/Egress Packet Rate

d)

Multi-Core Monitor

e)

Ingress/Egress Packet Size

54.

Which file types can be used to export logs? (Select all that apply)

a)

CSV

b)

PDF

c)

TEXT

d)

Email

55.

What is the default timeout setting for administrator inactivity?

a)

5 Minutes

b)

10 Minutes

c)

15 Minutes

d)

30 Minutes

56.

What type of encoding format is supported when importing an end-user certificate with a private key?

a)

DER

b)

PEM

c)

PKCS#12

d)

X.509

57.

Which SonicOS GUI option is used to create a snapshot of the current system state?

a)

Save Configuration

b)

Create Backup

c)

Export Settings

d)

Snapshot Generator

58.

Which interface is used by SonicOS as the backup heartbeat link for HA (High Availability)?

a)

X0

b)

X1

c)

X2

d)

X3

59.

The firewall snapshot section displays the percentage of encrypted traffic flowing through the firewall.

a)

True

b)

False

60.

Which setting is used to turn on the CFS Security Service?

a)

Manage >> Security Config >> Content Filter >> Select "SonicWall CFS" for content Filter Type

b)

Manage >> Firewall Settings >> Enable CFS Security

c)

Network >> Security Services >> Enable Content Filtering

d)

AppFlow >> Content Security >> Enable CFS

61.

Which Security Configuration menu option is used to enable client DPI-SSL?

a)

Manage >> Security Config >> Decryption Services >> General Tab, then check the box "Enable SSL Client Inspection"

b)

Network >> DPI-SSL >> Enable DPI-SSL for all traffic

c)

Security Services >> SSL Configuration >> Enable DPI-SSL

d)

Firewall >> DPI Settings >> Enable SSL Decryption

62.

Which of the following security features is enabled along with DPI-SSL? (Select all that apply)

a)

Intrusion Prevention

b)

Gateway Anti-Virus

c)

Gateway Anti-Spyware

d)

Application Firewall

e)

Content Filter

63.

Which Match Object property will control what type of policy it can be used in?

a)

Policy Type

b)

Rule Condition

c)

Match Object Type

d)

Filter Category

64.

What are the key components of a CFS policy? (Select all that apply)

a)

Block

b)

Passphrase (Authenticate)

c)

Confirm

d)

Bandwidth Management

65.

Which Logs panel depicts the EICAR test virus file download?

a)

Investigate >> Logs >> Firewall Logs

b)

Investigate >> Logs >> Event Logs

c)

Security Services >> Logs >> Threat Reports

d)

Monitor >> Security Incidents

66.

A Site-to-Site VPN can allow simultaneous access to multiple remote servers. (True / False)

a)

True

b)

False

67.

Which statement about SonicWall Gateway Anti-Virus service is correct?

a)

It inspects all traffic that traverses the SonicWall Gateway

b)

It inspects all web application protocols, but ignores TCP streams

c)

It requires file-size limitations for scanning

d)

It does not support compressed traffic scanning

68.

Which of the following sentences is correct about High Availability (HA) configuration?

a)

High Availability does not support Portshield interfaces and Native Bridge mode

b)

HA supports all network interface configurations

c)

HA can be configured without additional hardware

d)

HA is enabled by default

69.

What type of NAT policies does a Public Server wizard create? (Select all that apply)

a)

Inbound NAT Policies

b)

Outbound NAT Policies

c)

Loopback NAT Policies

d)

Dynamic NAT Policies

70.

Which of the following is included in the output of a network probe? (Select all that apply)

a)

Probe Target

b)

Name

c)

Probe Type

d)

Local IP

e)

Gateway

71.

Which diagnostic utility on the SonicWall firewall allows you to look at the contents of IP packets traversing the firewall?

a)

Log Analyzer

b)

Packet Monitor

c)

Connection Tracker

d)

DPI Monitor

72.

What are the default Network Zones in SonicWall? (Select all that apply)

a)

MULTICAST

b)

VPN

c)

LAN

d)

DMZ

e)

WAN

73.

What are the default rules in SonicWall? (Select all that apply)

a)

LAN to WAN: Allow All

b)

WAN to LAN: Deny All

c)

LAN to LAN: Allow All

d)

WAN to WAN: Allow All

e)

DMZ to LAN/WAN: Deny All

74.

Advanced Threat Protection is enabled by default.

a)

True

b)

False

75.

What is the default IP address of a SonicWall appliance?

a)

192.168.1.1

b)

192.168.168.168

c)

10.0.0.1

d)

172.16.1.1

76.

App Rules are enabled by default.

a)

True

b)

False

77.

What is the default WAN interface in SonicWall?

a)

X0

b)

X1

c)

X2

d)

X3

78.

What is the default LAN interface in SonicWall?

a)

X0

b)

X1

c)

X2

d)

X3

79.

What is the default probing address for failover in SonicWall?

a)

google.com

b)

dns.sonicwall.com

c)

responder.global.sonicwall.com

d)

8.8.8.8

80.

What are the default Security Types in SonicWall? (Select all that apply)

a)

Trusted

b)

Public

c)

Untrusted

d)

SSLVPN

e)

Encrypted

81.

What formats are available for exporting Packet Monitor results? (Select all that apply)

a)

Libpcap

b)

Pcap

c)

Text

d)

HTML

e)

AppData

82.

What is visible on the Appliance Health Overview window? (Select all that apply)

a)

Top Spyware

b)

Top Viruses

c)

Top Users

d)

Top Intrusions

e)

Top Applications

83.

A customer has an established base of GVC VPN users with a WAN GroupVPN policy configured. The customer wants to implement SSL VPN users. Why must the GVC VPN users be converted to SSL VPN users?

a)

The SonicWall appliance does not support both types of VPN users simultaneously

b)

GVC VPN is outdated and no longer supported

c)

SSL VPN provides better performance than GVC VPN

d)

GVC VPN only works with specific firewall models

84.

SSL VPN eliminates the need for remote access authentication. (True / False)

a)

True

b)

False

85.

Which of the following correctly describes how a bandwidth management rule works?

a)

Can only be configured for outbound traffic from the firewall

b)

Applies only to individual VPN Security Associations

c)

Can be configured for all VPN traffic

d)

Applies only to inbound traffic from the WAN

86.

What are the benefits provided by a VPN? (Select all that apply)

a)

Securely connects distributed networks together

b)

Prevents denial-of-service attacks on remote connections

c)

Enables a remote connection to the LAN via the Internet

d)

Assures remote clients have up-to-date antivirus software

e)

Provides data confidentiality and sender authentication

87.

What benefits are provided by a VPN? (Select all that apply)

a)

Reporting

b)

Increased capacity

c)

Scalability

d)

Encryption

e)

Security

88.

Which of the following is the most basic firewall technology?

a)

Single Firewall

b)

Next-Generation Firewall (NGFW)

c)

Deep Packet Inspection

d)

Packet Filtering

89.

The default firewall access rule allows all communication from the LAN to the Internet.

a)

True

b)

False

90.

What are two advantages of using multiple firewalls?

a)

Protects restricted special resources

b)

Allows all network segments free access to other segments

c)

Helps protect entire departments

d)

Reduces firewall configuration complexity

91.

What is the purpose of a security policy?

a)

To authenticate users and devices before granting network access

b)

To monitor network security and configure firewalls to prevent misuse

c)

To make it more difficult for hackers to locate a security hole in a network

d)

To describe how a company approaches security, including rules of conduct and acceptable risk

92.

What question would you ask to get specific information on user restrictions?

a)

What kinds of network traffic will you allow?

b)

Will the computers be locked away from the public, or will they have access to the hardware?

c)

Will users be allowed to log in at any time, from any location, to any machine?

d)

Who should be allowed to access your services?

93.

Content Filtering Services applies to which of the following traffic protocols?

a)

HTTPS

b)

FTP

c)

HTTP

d)

Email attachments

94.

If the appliance loses connection to the SonicWall site rating library, what actions can it take? (Select all that apply)

a)

CFS blocks all web traffic (based on configuration)

b)

CFS continues to operate using the last ratings seen

c)

CFS allows all web traffic (based on configuration)

d)

CFS must use its internal logic to identify which traffic to block

95.

With SonicWall CFS, network administrators have a flexible tool to provide comprehensive filtering based on which of the following? (Select all that apply)

a)

Time of day

b)

Allowed domain designations

c)

SMTP

d)

Keywords

e)

Forbidden domain designations

96.

The default CFS policy when assigned "Via Users and Zones Screens" should be the most restrictive. (True / False)

a)

True

b)

False

97.

The SonicWall Log can be exported in the following formats: (Select all that apply)

a)

Log View

b)

Team-separated value (CSV)

c)

Comma-separated value (CSV)

d)

Tab Delimited

e)

Plain text

98.

What options are used to preempt an administrator logged into the firewall? (Select all that apply)

a)

Log Out

b)

Drop into Non-config Mode

c)

Reset Firewall

d)

Disable Admin Access

99.

Which of the following network applications are available by default in the APP Rule Guide to create policies? (Select all that apply)

a)

FTP File Transfer

b)

SMTP Email

c)

Web Access

d)

POP3 Email

100.

The default Guest Profile cannot be deleted.

a)

True

b)

False

101.

What type of mapping does ARP (Address Resolution Protocol) enable?

a)

IP address to MAC address

b)

MAC address to IP address

c)

Domain name to IP address

d)

IP address to domain name

102.

Which firewall network setting allows the current state of the DHCP leases in the network to be periodically written to Flash?

a)

DHCP Lease Scavenging

b)

DHCP Lease Synchronization

c)

Enable DHCP Server Persistence

d)

DHCP Binding

103.

Which advanced network interface setting on the SonicWall NSv firewall allows initial packets or response packets to pass through other interfaces?

a)

Path MTU Discovery

b)

Proxy ARP

c)

Enable Asymmetric Route Support

d)

IP Spoof Detection

104.

Which of the following DDNS Providers are supported in SonicOS?

a)

DynDNS

b)

No-IP

c)

Google DNS

d)

ChangeIP

105.

The SonicOS NSv scheme of interface addressing works in conjunction with address objects, service objects, and network zones.

a)

True

b)

False

106.

The Public Server guide assigns the server automatically to the zone to which its IP address belongs

a)

True

b)

False

107.

When configuring a Site-to-Site policy, the Local Network option must match the Destination Network on the other side of the tunnel, in order to avoid tunnel negotiation errors or even a total failure.

a)

True

b)

False

108.

Which of the following is the default public server type?

a)

FTP Server

b)

VPN Server

c)

Web Server

d)

Mail Server

109.

What options are used to preempt an administrator logged into the firewall?

a)

Log out

b)

Simultaneous configuration

c)

Drop into Non-Config mode

d)

Deny access

110.

What are some of the key features of SonicWall Next-Gen firewalls?

a)

Network Segmentation,

b)

Flexible Deployment

c)

Application intelligence

d)

Control

111.

What are some of the key features of SonicOS 7 architecture?

a)

Advanced protection against encrypted threats,

b)

Simplified integration

c)

Easy zero-touch deployment

d)

TLS 1.3

112.

Select two best practices that should be implemented before updating the firewall firmware.

a)

Download a settings file locally

b)

Use the create backup option built into the firewall

c)

Create a HA pair

d)

Reboot the firewall

113.

The default mode of NSv is

a)

Transparent Mode

b)

Policy Mode

c)

Layer 2 Bridge Mode

d)

NAT Mode

114.

Static routes, by default, take precedence over VPN traffic.

a)

True

b)

False

115.

Routing applies to packets as they exit from the firewall

a)

True

b)

False

116.

Which of the following are included in the output of a network monitor?

a)

Probe Type

b)

Probe Target,

c)

IP Version,

d)

Interface

e)

CPU Usage

117.

What type of intermediate traffic is monitored by the Packet Monitor?

a)

Encrypted Packets

b)

Multicast packets that are replicated

c)

IP Helper-generated

d)

Encrypted VPN traffic payloads

118.

Which of the following are available in with the Basic Capture Client License? (Select all that apply)

a)

Integration with Capture Security Center

b)
  • Role-based access control

c)

Device Control & Network Access Control

d)

Windows Server Support

119.

Application Vulnerability Intelligence helps catalog every application on each protected endpoint.

a)

True

b)

False

120.

Which packet status types are indicated by the Packet Monitor?

a)

Dropped

b)

Forwarded

c)

Encrypted

d)

Consumed

121.

NSM on prem offers large scale centralized management of SonicWall Gen 7 devices only?

a)

True

b)

False

122.

Export formats for snapshot of Packet Monitor include:

a)

HTML

b)

CSV

c)

PCAP

d)

Plain Text

123.

Keep Alive should be enabled on the firewall with the most processing overhead

a)

True

b)

False

124.

What is the default session time an administrator can be logged into the firewall

a)

30 min

b)

15 min

c)

5 min

d)

10 min

125.

What user authentication should be used for groups with more than 1000 users and provides an extra layer of security?

a)

Radius

b)

LDAP

c)

Local Users

d)

TLS

126.

The SonicWall Administrator has modified the default LAN > WAN access rule from "allow" to "deny", blocking all outbound WAN traffic. Which of the following statements is true?

a)

LAN users can still access the internet because stateful packet inspection allows return traffic.

b)

LAN users cannot access the internet, but the firewall can still register with mysonicwall.com and update UTM signatures.

c)

The firewall will block all outbound traffic, including its own updates and registrations.

d)

LAN users can still access the internet, but only over non-standard ports.

127.

When creating a site to site VPN, the policy type should be set to?

a)

Tunnel Interface

b)

Site to Site

c)

IKE using Preshared Secret

d)

Multiple Site

128.

When creating a Route-Based VPN in SonicOS 7, the policy type should be set to?

a)

IPSec Keying Mode

b)

Tunnel Interface

c)

Main Mode

d)

Site-to-Site

129.

Which protocol provides separate Authentication, Authorization, and Accounting (AAA) services?

a)

Radius +

b)

TACACS +

c)

LDAP

d)

Kerberos

130.

The NSM Closed Network Support feature is ideal for customers who run:

a)

Public cloud-based infrastructures

b)

One or more private networks that are completely shut off from the outside environment

c)

Small office/home office (SOHO) networks

d)

Hybrid Clouds

131.

NSM On-Prem requires a separate license for the reporting and analytics features

a)

True

b)

False

132.

Setting the Event Priority level lower than the Logging Level will cause those events to be filtered out from Event Logs

a)

True

b)

False

133.

If the Logging Level Filter is defined as Error, which of the following alert messages will also be displayed in the results?

a)

Emergency

b)

Informational

c)

Critical

d)

Alert

e)

Warning

134.

Advanced routing is enabled by default?

a)

True

b)

False

135.

Which of the following variables are used to configure static routes to forward traffic?

a)

Interfaces

b)

Services

c)

Source MAC address

d)

Destination MAC address

136.

Which protocols are supported by the Advanced Routing mode of SonicWall NSv?

a)

RIP

b)

OSPFv3

c)

EIGRP

d)

Bridge Mode

137.

Who among the following can manage Guest Accounts and Sessions

a)

Guest Administrators

b)

Limited Administrator

c)

Firewall Operator

d)

JIT Administrator

138.

Which of the following are the default user groups to which a new user is automatically added in a SonicWall firewall?

a)

Trusted Users

b)

Guest Services

c)

Administrators

d)

SSLVPN Users

e)

Everyone

139.

Which user authentication methods are available in a SonicWall NSv?

a)

Local User

b)

RADIUS

c)

TACACS +

d)

LDAP

e)

SSO

140.

A Site-to-Site VPN can allow simultaneous access to multiples remote servers

a)

tRUE

b)

fALSE

141.

Which of the following sentences is correct about HA configuration?

a)

HA can be configured without additional hardware

b)

HA is enabled by default

c)

High Availability cannot be configured while there are ports participating in PortShield

d)

HA supports all network interface configurations

142.

Enhanced Security Mode enables

a)

Maximum security by inspecting all content with any threat probability - High, Medium or Low

b)

Maximum security by inspecting all content with any threat probability - High or Medium.

c)

Maximum security by inspecting all content with any defined threat level.

d)

Maximum security by inspecting all content with a Low threat probability

143.

A major advantage of a route based VPN is

a)

It provides flexibility on how traffic is routed

b)

It requires less configuration than policy-based VPNs

c)

It does not support multiple subnets

d)

It eliminates the need for a VPN gateway

144.

Before registering a firewall, a MySonicWall account needs to be created

a)

True

b)

False

145.

Select the two methods used to register the SonicWall appliance

a)

Manual Registration via MySonicWall

b)

Through the SonicOS web management interface

c)

Offline Registration via USB Drive

d)

Command Line Registration using SSH

146.

Enabling HTTPS management of the WAN interface is considered a best practice

a)

True

b)

False

147.

The interface through which the firewall is managed can be disabled

a)

True

b)

False

148.

A custom service object cannot be created

a)

True

b)

False

149.

Which object represents a cluster of multiple services for security filtering?

a)

Security Policy

b)

App Rule

c)

Service Group

d)

Address Object

150.

In order for SonicWall1's Deep Packet Inspection engine to provide protection, where must GAV, IPS, and Gateway Anti-Spyware be enable?

a)

Security Services

b)

Zones

c)

Firewall Access Rules

d)

Interface settings

e)

DPI-SSL settings

151.

What is the default user authentication method in the firewall?

a)

Local Users

b)

Radius

c)

LDAP

d)

SAML

152.

What port number is used for SSO?

a)

443

b)

3389

c)

2258

d)

639

153.

What type of encoding format includes a private key inside?

a)

PEM

b)

CER

c)

PKCS#12

d)

DER

154.

In SonicWall, what is the maximum number of entries that can be configured for Split DNS?

a)

5

b)

10

c)

50

d)

32

155.

What is the purpose of maintaining an ARP cache in the firewall?

a)

minimize the broadcast traffic,

b)

store and reuse the earlier ARP information

c)

Enhances the performance of routing by storing IP routing tables

d)

Allows the firewall to track the availability of remote network resources