FDmp
|
|
Título del Test:
![]() FDmp Descripción: f o r t i |



| Comentarios |
|---|
NO HAY REGISTROS |
|
Which two pieces of information are synchronized between FortiGate HA members? (Choose two.). BGP peerings. OSPF adjacencies. DHCP leases. IPsec security associations. How can you disable RPF checking?. Disable src-check on the interface level settings. Disable strict-src-check under system settings. Disable fail-detect on the interface level settings. Unset fail-alert-interfaces on the interface level settings. An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page. Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?. On the Static URL Filter configuration, set Action to Exempt. On the Static URL Filter configuration, set Action to Monitor. On the Static URL Filter configuration, set Type to Simple. On the FortiGuard Category Based Filter configuration, set Action to Warning for Social Networking. An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24. which subnet must the administrator configure for the local quick mode selector for site B?. 192.168.0.0/8. 192.168.3.0/24. 192.168.2.0/24. 192.168.1.0/24. Refer to the exhibit, which contains a RADIUS server configuration. An administrator added a configuration for a new RADIUS server. While configuring, the administrator enabled Include in every user group. What is the impact of enabling Include in every user group in a RADIUS configuration?. This option places all users into every RADIUS user group, including groups that are used for the LDAP server on FortiGate. This option places the RADIUS server, and all users who can authenticate against that server, into every FortiGate user group. This option places the RADIUS server, and all users who can authenticate against that server, into every RADIUS group. This option places all FortiGate users and groups required to authenticate into the RADIUS server, which, in this case, is FortiAuthenticator. A FortiGate administrator is required to reduce the attack surface on the SSL VPN portal. Which SSL timer can you use to mitigate a denial of service (DoS) attack?. SSL VPN http-request-header-timeout. SSL VPN idle-timeout. SSL VPN dt1s-hello-timeout. SSL VPN login-timeout. What are three key routing principles in SD-WAN? (Choose three.). By default, SD-WAN rules are skipped if the best route to the destination is not an SD-WAN member. Regular policy routes have precedence over SD-WAN rules. By default, SD-WAN members are skipped if they do not have a valid route to the destination. By default, SD-WAN rules are skipped if only one route to the destination is available. SD-WAN rules have precedence over any other type of routes. The NOC team connects to the FortiGate GUI with the NOC_Access admin profile. They request that their GUI sessions do not disconnect too early during inactivity. What must the administrator configure to answer this specific request from the NOC team?. Increase the admintimeout value under config system accprofile Noc_Access. Ensure that all NOC_Access users are assigned the super_admin role to guarantee access. Increase the offline value of the override Idle Timeout parameter in the NOC_Access admin profile. Move NOC_Access to the top of the list to ensure all profile settings take effect. Which statement about this firewall policy list is true?. LAN to WAN, WAN to LAN. And Implicit are sequence grouping view lists. The Implicit group can include more than one deny firewall policy. The firewall policies are listed by ID sequence view. The firewall policies are listed by ingress and egress interfaces pairing view. Which statement correctly describes NetAPI polling mode for the FSSO collector agent?. The NetSessionEnum function is used to track user logouts. The collector agent must search Windows application event logs. NetAPI polling can increase bandwidth usage in large networks. The collector agent uses a Windows API to query DCs for user logins. Refer to the exhibits, which show the firewall policy and the security profile for Facebook. Users are given access to the Facebook web application. They can play video content hosted on Facebook, but they are unable to leave reactions on videos or other types of posts. Which part of the configuration must you change to resolve the issue?. Add Facebook to the URL category in the security policy. Get the additional application signatures required to add to the security policy. Disable HTTP redirect to HTTPS on the web browser. Make the SSL inspection a deep content inspection. Refer to the exhibits, which show the firewall policy and an antivirus profile configuration. Why is the user unable to receive a block replacement message when downloading an infected file for the first time?. Flow-based inspection is used, which resets the last packet to the user. The intrusion prevention security profile must be enabled when using flow-based inspection mode. The firewall policy performs a full content inspection on the file. The option to send files to FortiSandbox for inspection is enabled. Refer to the exhibit. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 status is up, but phase 2 fails to come up. Based on the phase 2 configuration shown in the exhibit, which two configuration changes will bring phase 2 up? (Choose two.). On BR1-FGT, set Remote Address to 10.0.11.0/255.255.255.0. On BR1-FGT, set Seconds to 43200. On HQ-NGFW, enable Diffie-Hellman Group 2. On HQ-NGFW, set Encryption to AES256. A FortiGate firewall policy is configured with active authentication, however, the user cannot authenticate when accessing a website. Which protocol must FortiGate allow even though the user cannot authenticate?. DNS. Kerberos. TACACS+. LDAP. Which two statements explain antivirus scanning modes? (Choose two.). In proxy-based inspection mode, files bigger than the buffer size are scanned. In flow-based inspection mode, files bigger than the buffer size are scanned. In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client. In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client. Which three CLI commands can you use to troubleshoot Layer 3 issues, if the issue is in neither the physical layer nor the link layer? (Choose three.). diagnose sys top. diagnose sniffer packet any. execute ping. execute traceroute. get system arp. An administrator has configured a strict RPF check on FortiGate. How does strict RPF check work?. Strict RPF checks only for the existence of at least one active route back to the source using the incoming interface. Strict RPF check is run on the first sent and reply packet of any new session. Strict RPF checks the best route back to the source using the incoming interface. Strict RPF allows packets back to sources with all active routes. What are two features of collector agent advanced mode? (Choose two.). Advanced mode uses the Windows convention-NetBios: Domain\Username. In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate. Advanced mode supports nested or inherited groups. In advanced mode, security profiles can be applied only to user groups, not individual users. Which three statements explain a flow-based antivirus profile? (Choose three.). Flow-based inspection optimizes performance compared to proxy-based inspection. FortiGate buffers the whole file but transmits to the client at the same time. If a virus is detected, the last packet is delivered to the client. The IPS engine handles the process as a standalone. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection. What are two features of FortiGate FSSO agentless polling mode? (Choose two.). FortiGate does not support workstation check. FortiGate uses the AD server as the collector agent. FortiGate directs the collector agent to use a remote LDAP server. FortiGate uses the SMB protocol to read the event viewer logs from the DCs. Based on the output, which two facts does the administrator know about the FortiGuard connection? (Choose two.). FortiGate is using default FortiGuard communication settings. A local FortiManager is one of the servers FortiGate communicates with. There is at least one server that lost packets consecutively. One server was contacted to retrieve the contract information. An administrator has configured the following settings: config system settings set ses-denied-traffic enable end config system global set block-session-timer 30 end What are the two results of this configuration? (Choose two.). Device detection on all interfaces is enforced for 30 minutes. A session for denied traffic is created. The number of logs generated by denied traffic is reduced. Denied users are blocked for 30 minutes. An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric After synchronization, this object is not available on the downstream FortiGate (ISFW). What must the administrator do to synchronize the address object?. Change the csf setting on both devices to set downstream-access enable. Change the csf setting on ISFW (downstream) to set configuration-sync local. Change the csf setting on ISFW (downstream) to set authorization-request-type certificate. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default. A network administrator enabled antivirus and selected an SSL inspection profile on a firewall policy. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and does not block the file, allowing it to be downloaded. The administrator confirms that the traffic matches the configured firewall policy. What are two reasons for the failed virus detection by FortiGate? (Choose two.). The browser does not trust the FortiGate self-signed CA certificate. The website is exempted from SSL inspection. The selected SSL inspection profile has certificate inspection enabled. The EICAR test file exceeds the protocol options oversize limit. An administrator wants to configure dead peer detection (DPD) on IPsec VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when there is no inbound traffic. Which DPD mode on FortiGate meets this requirement?. On Demand. On Idle. Disabled. Enabled. FortiGate is operating in NAT mode and has two physical interfaces connected to the LAN and DMZ networks respectively. Which two statements about the requirements of connected physical interfaces on FortiGate are true? (Choose two.). Both interfaces must Have DHCP enabled and interfaces set to LAN and DMZ roles assigned. Both interfaces must have the interface role assigned. Both interfaces must have directly connected routes on the routing table. Both interfaces must have IP addresses assigned. Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which additional configuration can the administrator add to a deny firewall policy, beyond the default behavior, to block Remote-User2 from accessing the Webserver?. Set the Destination address Deny_IP in the Allow_access policy. Configure a One-to-One IP Pool object in a new policy. Set the Destination address as Webserver in the Deny policy. Disable match-vip in the Allow_access policy. What two conclusions can you make from the debug flow output? (Choose two.). The default route is required to receive a reply. A firewall policy allowed the connection. A new traffic session was created. The debug flow is for ICMP traffic. The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router. When the administrator tries to access the webserver public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output. Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?. Enable port forwarding on the server to map the external service port to the internal service port. In the VIP configuration, enable arp-reply. Configure a loopback interface with address 203.0.113.2/32. In the firewall policy configuration, enable match-vip. Examine the intrusion prevention system (IPS) diagnostic command shown in the exhibit. if option 5 is used with the IPS diagnostic command and the outcome is a decrease in the CPU usage, what is the correct conclusion?. The IPS engine is blocking all traffic. The IPS engine is unable to prevent an intrusion attack. The IPS engine is inspecting a high volume of traffic. The IPS engine will continue to run in a normal state. FortiGuard categories can be overridden and defined in different categories. To create a web rating override for the example.com homepage, the override must be configured using a specific syntax. Which two syntaxes are correct to configure a web rating override for the home page? (Choose two.). www.example.com. www.example.com: 443. www.example.com/index.html. example.com. A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors. What is the reason for the certificate warning errors?. The matching firewall policy is set to proxy inspection mode. The option invalid SSL certificates is set to allow on the SSL/SSH inspection profile. The browser does not trust the certificate used by FortiGate for SSL inspection. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions. FortiGate has two separate firewall policies for Sales and Engineering to access the same web server with the same security profiles. Which action must the administrator perform to consolidate the two policies into one?. Create an Interface Group that includes port1 and port2 to create a single firewall policy. Select port1 and port2 subnets in a single firewall policy. Replace port1 and port2 with the any interface in a single firewall policy. Enable Multiple Interface Policies to select port1 and port2 in the same firewall policy. Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?. Intrusion prevention system engine. Internet Service Database (ISDB) engine. Antivirus engine. Application control engine. Which statement is correct regarding the use of application control for inspecting web applications?. Application control signatures are included in Fortinet Antivirus engine. Application control does not require SSL inspection to identify web applications. Application control does not display a replacement message for a blocked web application. Application control can identify child and parent applications, and perform different actions on them. Refer to the exhibits. The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to the SSL VPN?. Change the SSL VPN portal to the tunnel. Change the idle-timeout. Change the server IP address. Change the SSL VPN port on the client. Based on the routing database shown in the exhibit, which two conclusions can you make about the routes? (Choose two.). The port3 default route has the lowest metric. The port3 default route has the highest distance. The port1 and port2 default routes are active in the routing table. There will be eight routes active in the routing table. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies configuration, VIP configuration, and IP pool configuration on the FortiGate device. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.1.10?. 10.200.1.10. 10.200.1.100. 10.200.1.1. 10.0.1.254. Which two statements are correct when the FortiGate device enters conserve mode? (Choose two.). FortiGate continues to run critical security actions, such as quarantine. FortiGate refuses to accept configuration changes. FortiGate halts complete system operation and requires a reboot to regain available resources. FortiGate continues to transmit packets without IPS inspection when the fail-open global setting in IPS is enabled. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. If the host 10.200.3.1 sends a TCP SYN packet on port 8080 to 10.200.1.10, what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination?. 10.0.1.254, 10.0.1.10, and 80, respectively. 10.200.3.1, 10.0.1.10, and 80, respectively. 10.0.1.254, 10.200.1.10, and 8080, respectively. 10.200.3.1, 10.0.1.10, and 8080, respectively. An intrusion prevention system (IPS) profile signature setting is shown. What can you conclude about the signature when adding the FTP.Login.Failed signature to the IPS Sensor profile?. FortiGate allows this low severity signature packet and creates a log. The signature setting includes a group of other signatures. FortiGate stores a local copy of the packet that matches the signature. The signature setting uses a custom rating threshold. Which two attributes are required on a certificate so it can be used as a CA certificate on SSL inspection? (Choose two.). The Authority Key Identifier must be of type SSL. The keyUsage extension must be set to keyCertSign. The CA extension must be set to TRUE. The issuer must be a public CA. Refer to the exhibits. Based on the current HA status, an administrator updates the override and priority parameters on HQ-NGFW-1 and HQ-NGFW-2 as shown in the exhibits. What would be the expected outcome in the HA cluster?. HQ-NGFW-1 will remain the primary because HQ-NGFW-2 has lower priority. The HA cluster will become out of sync because the override setting must match on all HA members. HQ-NGFW-1 will synchronize the override disable setting with HQ-NGFW-2. HQ-NGFW-2 will take over as the primary because it has the override enable setting and higher priority than HQ-NGFW-1. Refer to the exhibit. The administrator configured SD-WAN rules and set the FortiGate traffic log page to display SD-WAN-specific columns: SD-WAN Quality and SD-WAN Rule Name. FortiGate allows the traffic according to policy ID 1 placed at the top. This is the policy that allows SD-WAN traffic. Despite these settings, the traffic logs do not show the name of the SD-WAN rule used to steer those traffic flows. What could be the reason?. SD-WAN rule names do not appear immediately. The administrator must refresh the page. There is no application control profile applied to the firewall policy. FortiGate load balanced the traffic according to the implicit SD-WAN rule. Destinations in the SD-WAN rules are configured for each application, but feature visibility is not enabled. There are multiple dialup IPsec VPNs configured in aggressive mode on the HQ FortiGate. The requirement is to connect dial-up users to their respective department VPN tunnels. Which phase 1 setting you can configure to match the user to the tunnel?. Dead Peer Detection. Peer ID. Local Gateway. IKE Mode Config. An organization requires remote users to send external application data running on their PCs and access FTP resources through an SSL/TLS connection. Which FortiGate configuration can achieve this goal?. Zero trust network access. SSL VPN tunnel. SSL VPN quick connection. SSL VPN bookmark. Which statement about the deployment of the Security Fabric in a multi-VDOM environment is true?. Security rating reports can be run individually for each configured VDOM. Downstream devices can connect to the upstream device from any of their VDOMs. VDOMs without ports with connected devices are not displayed in the topology. Each VDOM in the environment can be part of a different Security Fabric. Which two statements are true about the FGCP protocol? (Choose two.). FGCP is used to discover FortiGate devices in different HA groups. FGCP elects the primary FortiGate device. FGCP is not used when FortiGate is in transparent mode. FGCP runs only over the heartbeat links. An administrator must enable a DHCP server on one of the directly connected networks on FortiGate. However, the administrator is unable to complete the process on the GUI to enable the service on the interface. In this scenario, what prevents the administrator from enabling DHCP service?. The DHCP server setting IS available only on the CLI. The FortiGate model does not support the DHCP server. The role of the interface prevents setting a DHCP server. Another interface is configured as the only DHCP server On FortiGate. Which three statements about SD-WAN zones are true? (Choose three.). You can define up to three SD-WAN zones per FortiGate device. An SD-WAN zone is a logical grouping of members. You can use an SD-WAN zone in static route definitions. An SD-WAN zone can contain physical and logical interfaces. An SD-WAN zone must contains at least two members. Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three). The subject alternative name (SAN) field in the server certificate. The serial number in the server certificate. The host field in the HTTP header. The subject field in the server certificate. The server name indication (SNI) extension in the client hello message. Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?. Traffic matching the signature will be silently dropped and logged. Traffic matching the signature will be allowed and logged. The signature setting uses a custom rating threshold. The signature setting includes a group of other signatures. The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?. Static URL filter, FortiGuard category filter, and advanced filters. DNS based web filter and proxy based web filter. Static domain filter, SSL inspection filter, and external connectors filters. FortiGuard category filter and rating filter. Refer to the exhibit to view the firewall policy. Why would the firewall policy not block a well-known virus, for example eicar?. The firewall policy does not apply deep content inspection. Web filter should be enabled on the firewall policy to complement the antivirus profile. The action on the firewall policy must be set to deny. The firewall policy must be configured in proxy-based inspection mode. The exhibit contains a network diagram, central SNAT policy, and IP pool configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. A firewall policy is configured to allow all destinations from LAN (port3) to WAN (port1). Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied. Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?. 10.200.1.49. 10.200.1.149. 10.200.1.1. 10.200.1.99. In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output as shown in the exhibit. What should the administrator do next to troubleshoot the problem?. Execute a debug flow. Run a sniffer on the web server. Capture the traffic using an external sniffer connected to port1. Execute another sniffer in the FortiGate, this time with the filter "host 10.0.1.10". What is the primary FortiGate election process when the HA override setting is disabled?. Connected monitored ports > HA uptime > Priority > FortiGate Serial number. Connected monitored ports > Priority > HA uptime > FortiGate Serial number. Connected monitored ports > Priority > System uptime > FortiGate Serial number. Connected monitored ports > System uptime > Priority > FortiGate Serial number. Which two statements describe how the RPF check is used? (Choose two.). RPF is a mechanism that protects FortiGate and your network from IP spoofing attacks. The RPF check is run on the first sent and reply packet of any new session. The RPF check is run on the first reply packet of any new session. The RPF check is run on the first sent packet of any new session. Which inspection mode does FortiGate use for application profiles if it is configured as a profile-based next-generation firewall (NGFW)?. Full Content inspection. Flow-based inspection. Certificate inspection. Proxy-based inspection. A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match. Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.). On Remote FortiGate, set port2 as Interface. On HQ-FortiGate, disable Diffie-Helman group2. On HQ-FortiGate, set IKE mode to Main (ID protection). On both FortiGate devices, set Dead Peer Detection to On Demand. A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two IPsec VPN tunnels and static routes. 1. All traffic must be routed through the primary tunnel when both tunnels are up 2. The secondary tunnel must be used only if the primary tunnel goes down 3. In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover Which two key configuration changes are needed on FortiGate to meet the design requirements? (Choose two). Configure a higher distance on the static route for the primary tunnel, and a lower distance on the static route for the secondary tunnel. Enable Auto-negotiate and Autokey Keep Alive on the phase 2 configuration of both tunnels. Enable Dead Peer Detection. Configure a lower distance on the static route for the primary tunnel, and a higher distance on the static route for the secondary tunnel. The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile. An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category. What are two solutions for satisfying the requirement? (Choose two.). Configure a web override rating for download.com and select Malicious Websites as the subcategory. Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address. Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively. Set the Freeware and Software Downloads category Action to Warning. An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings. What is true about the DNS connection to a FortiGuard server?. It uses DNS over HTTPS. It uses UDP 8888. It uses UDP 53. It uses DNS over TLS. Which two features of IPsec IKEv1 authentication are supported by FortiGate? (Choose two.). No certificate is required on the remote peer when you set the certificate signature as the authentication method. Extended authentication (XAuth) for faster authentication because fewer packets are exchanged. Extended authentication (XAuth) to request the remote peer to provide a username and password. Pre-shared key and certificate signature as authentication methods. Refer to the exhibits. The exhibits show the system performance output and default configuration of high memory usage thresholds on a FortiGate device. Based on the system performance output, what are the two possible outcomes? (Choose two.). FortiGate drops new sessions. Administrators can change the configuration. FortiGate has entered conserve mode. Administrators can access FortiGate only through the console port. Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.). The client FortiGate requires a manually added route to remote subnets. The client FortiGate requires a client certificate signed by the CA on the server FortiGate. The server FortiGate requires a CA certificate to verify the client FortiGate certificate. The client FortiGate uses the SSL VPN tunnel interface type to connect SSL VPN. FortiGate is integrated with FortiAnalyzer and FortiManager. When a firewall policy is created, which attribute is added to the policy to improve functionality and to support recording logs to FortiAnalyzer or FortiManager?. Policy ID. Universally Unique Identifier. Sequence ID. Log ID. Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy, and the sniffer CLI output on the FortiGate device. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The webserver host (10.0.1.10) must use its VIP external IP address as the source NAT (SNAT) when it pings remote server (10.200.3.1). Which two statements are valid to achieve this goal? (Choose two.). Create a new firewall policy before Internet_Access for the webserver and apply the IP pool. Enable NAT on the Allow_access firewall policy. Disable port forwarding on the VIP object. Disable NAT on the Internet_Access firewall policy. Refer to the exhibits. The exhibits show the application sensor configuration and the Excessive-Bandwidth and Apple filter details. Based on the configuration, what will happen to Apple FaceTime if there are only a few calls originating or incoming?. Apple FaceTime will be allowed, based on the Video/Audio category configuration. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration. Apple FaceTime will be allowed only if the Apple filter in Application and Filter Overrides is set to Allow. Apple FaceTime will be allowed, based on the Apple filter configuration. Which two statements are true about the routing entries in this database table? (Choose two.). All of the entries in the routing database table are installed in the FortiGate routing table. The default route on port2 is marked as the standby route. The port2 interface is marked as inactive. Both default routes have different administrative distances. Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet. Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.). Configure another firewall policy that matches only the address of PC3 as source, and then place the policy on top of the list. In the IP pool configuration, set endip to 192.2.0.12. In the firewall policy configuration, add 10.0.1.3 as an address object in the source field. In the IP pool configuration, set type to overload. What are two features of the NGFW profile-based mode? (Choose two.). NGFW profile-based mode supports applying applications and web filtering profiles in a firewall policy. NGFW profile-based mode must require the use of central source NAT policy. NGFW profile-based mode policies support both flow inspection and proxy inspection. NGFW profile-based mode can only be applied globally and not on individual VDOMs. Which two statements are true regarding FortiGate HA configuration synchronization? (Choose two.). Incremental configuration synchronization can occur only from changes made on the primary FortiGate device. Checksums of devices are compared against each other to ensure configurations are the same. Checksums of devices will be different from each other because some configuration items are not synced to other HA members. Incremental configuration synchronization can occur from changes made on any FortiGate device within the HA cluster. A network administrator has configured an SSL/SSH inspection profile defined for full SSL inspection and set with a private CA certificate. The firewall policy that allows the traffic uses this profile for SSL inspection and performs web filtering. When visiting any HTTPS websites, the browser reports certificate warning errors. What is the reason for the certificate warning errors?. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions. The browser does not recognize the certificate in use as signed by a trusted CA. With full SSL inspection it is not possible to avoid certificate warning errors at the browser level. The SSL cipher compliance option is not enabled on the SSL inspection profile. This setting is required when the SSL inspection profile is defined with a private CA certificate. A network administrator is configuring an IPsec VPN tunnel for a sales employee travelling abroad. Which IPsec Wizard template must the administrator apply?. Dial up User. Hub-and-Spoke. Remote Access. Site to Site. When FortiGate performs SSL/SSH full inspection, you can decide how it should react when it detects an invalid certificate. Which three actions are valid actions that FortiGate can perform when it detects an invalid certificate? (Choose three.). Trust & Allow. Block & Warning. Allow & Warning. Block. Allow. Refer to the exhibit, which shows a partial configuration from the remote authentication server. Why does the FortiGate administrator need this configuration?. To authenticate and match the Training OU on the RADIUS server. To authenticate Any FortiGate user groups. To authenticate only the Training user group. To set up a RADIUS server Secret. An administrator manages a FortiGate model that supports NTurbo. How does NTurbo acceleration enhance antivirus performance?. For proxy-based inspection, NTurbo buffers the whole file and then sends it to the antivirus engine. For flow-based inspection, NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces. For flow-based inspection, NTurbo creates two inspection sessions on the FortiGate device. For proxy-based inspection, NTurbo offloads traffic to the content processor. An administrator configured a FortiGate device to act as a collector for agentless polling mode. What must the administrator add to the FortiGate device to retrieve AD user group information?. TACACS server. Keycloak server. RADIUS server. LDAP server. Which algorithm does SD-WAN use to distribute traffic that does not match any of the SD-WAN rules?. Traffic is sent to the link with the lowest latency. Traffic is distributed based on the number of sessions through each interface. All traffic from a source IP is sent to the same interface. All traffic from a source IP to a destination IP is sent to the same interface. Which statement is a characteristic of automation stitches?. They can be created only on downstream devices in the fabric. They can have one or more triggers. They can run multiple actions at the same time. They can be run only on devices in the Security Fabric. Which method allows management access to the FortiGate CLI without network connectivity?. Serial console. CLI console widget. SSH console. Telnet console. Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?. The d-wan zone cannot be deleted. The underlay zone contains port1 and port2. The virtual-wan-link zone contains no member. The d-wan zone contains no member. An employee needs to connect to the office through a high-latency internet connection. Which SSL VPN setting should the administrator adjust to prevent SSL VPN negotiation failure?. SSL VPN session-ttl. SSL VPN dtls-hello-timeout. SSL VPN login-timeout. SSL VPN idle-timeout. Which three methods are used by the collector agent for AD polling? (Choose three.). FortiGate polling. WMI. FSSO REST API. WinSecLog. NetAPI. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.). The sensor will reset all connections that match these signatures. The sensor will block all attacks aimed at Windows servers. The sensor will gather a packet log for all matched traffic. The sensor will allow attackers matching the Microsoft.Windows.iSCSI.Target.DoS signature. Which three strategies are valid SD-WAN rule strategies for member selection? (Choose three.). Lowest Cost (SLA) without load balancing. Best Quality with load balancing. Lowest Quality (SLA) with load balancing. Lowest Cost (SLA) with load balancing. Manual with load balancing. Which two statements about equal-cost multi-path (ECMP) configuration on FortiGate are true? (Choose two.). If SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP. If SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based. SD-WAN is disabled, you configure the load balancing algorithm in config system settings. If SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode. Refer to the exhibit. When attempting to access an external website using an active authentication method, the user is not presented with a login prompt. What is the most likely reason for this situation?. The Remote-users group must be set up correctly in the FSSO configuration. The Service DNS is required in the firewall policy. The user is using an incorrect user name. No matching user account exists for this user. Refer to the exhibit. Why did FortiGate drop the packet?. It failed the RPF check. It matched an explicitly configured firewall policy with the action DENY. The next-hop IP address is unreachable. It matched the default implicit firewall policy. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?. 10.200.1.99. 10.200.1.149. 10.200.1.1. 10.200.1.49. As an administrator you have created an IPS profile, but it is not performing as expected. While testing you got the output as shown in the exhibit. What could be the possible reason of the diagnose output shown in the exhibit?. FortiGate entered into IPS fail open state. There is a no firewall policy configured with an IPS security profile. Administrator entered the command diagnose test application ipsmonitor 99. Administrator entered the command diagnose test application ipsmonitor 5. What would be the impact of these settings on the Server certificate SNI check configuration on FortiGate?. FortiGate will close the connection if the SNI does not match the CN or SAN fields. FortiGate will accept and use the CN in the server certificate for URL filtering if the SNI does not match the CN or SAN fields. FortiGate will close the connection if the SNI does not match the CN and SAN fields. FortiGate will accept the connection with a warning if the SNI does not match the CN or SAN fields. Refer to the exhibit. A partial cloud topology is shown. You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS. During the deployment, which components must the FortiGate CNF create to handle traffic from the EC2 instance?. The gateway load balancer endpoint (GWLBe) in the customer virtual private cloud (VPC). The GWLB, GWLBe, and the internet gateway (IGW) in the customer VPC. The CNF VPC, customer VPC, and GWLB. The customer VPC and GWLBe. Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. Which two factors can you observe from these configurations? (Choose two.). Facebook access is blocked based on the category filter settings. Facebook access is allowed but you cannot play Facebook videos based on Video/Audio category filter settings. YouTube search is allowed based on the Google Application and Filter override settings. YouTube access is blocked based on Excessive-Bandwidth Application and Filter override settings. An administrator has configured an Application Overrides for the ABC.Com application signature and set the Action to Allow. This application control profile is then applied to a firewall policy that is scanning all outbound traffic. Logging is enabled in the firewall policy. To test the configuration, the administrator accessed the ABC.Com web site several times. Why are there no logs generated under security logs for ABC.Com?. The ABC.Com is configured under application profile, which must be configured as a web filter profile. The ABC.Com Action is set to Allow. The ABC.Com is hitting the category Excessive-Bandwidth. The ABC.Com Type is set as Application instead of Filter. Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. You cannot access any of the Google applications, but you are able to access www.fortinet.com. Which two actions would you take to resolve the issue? (Choose two.). Add *Google*.com to the URL category in the security profile. Set the action for Google in the Application and Filter Overrides section to Allow. Set SSL inspection to deep-content inspection. Move up Google in the Application and Filter Overrides section to set its priority to 1. The predefined deep-inspection and custom-deep-inspection profiles exclude some web categories from SSL inspection, as shown in the exhibit. For which two reasons are these web categories exempted? (Choose two.). The resources utilization is optimized because these websites are in the trusted domain list on FortiGate. The legal regulation aims to prioritize user privacy and protect sensitive information for these websites. These websites are in an allowlist of reputable domain names maintained by FortiGuard. The FortiGate temporary certificate denies the browsers access to websites that use HTTP Strict Transport Security. Refer to the exhibits. A diagram of a FortiGate device connected to the network, as well as the firewall policy and IP pool configuration on the FortiGate device are shown. Two PCs, PC1 and PC2, are connected behind FortiGate and can access the internet successfully. However, when the administrator adds a third PC to the network (PC3), the PC cannot connect to the internet. Based on the information shown in the exhibit, which two configuration options can the administrator use to fix the connectivity issue for PC3? (Choose two.). In the IP pool configuration, set type to overload. In the IP pool configuration, set end ip to 100.65.0.112. In the system settings, set Multiple Interface Policies to enable. In the firewall policy, set match-vip to enable using CLI. How can the administrator view the log messages shown in the exhibit? (Choose two.). By right clicking the Implicit deny policy. Through Security event log page. Through FortiGate CLI command diagnose log test. Filtering by Policy UUID and Application Name in the log entry. Why is the Antivirus scan switch grayed out when you are creating a new antivirus profile for FTP?. Antivirus scan is disabled under system -> Feature visibility. FortiGate, with less than 2 GB RAM, does not support the Antivirus scan feature. The Feature Set for the profile is Flow-based but it must be Proxy-based. None of the inspected protocols are active in this profile. Refer to the exhibits. A diagram of a FortiGate device connected to the network VIP object and firewall policy configurations are shown. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. If the host 100.65.1.111 sends a TCP SYN packet on port 443 to 100.65.0.200, what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination?. 100.65.1.111, 10.0.11.50, and 443, respectively. 10.0.11.254, 100.65.0.200, and 443, respectively. 10.0.11.254, 10.0.15.50, and 4443, respectively. 100.65.1.111, 10.0.11.50, and 4443, respectively. Refer to the exhibits. A web filter profile configuration and firewall policy configuration are shown. You are trying to access www.facebook.com, but you are redirected to a FortiGuard web filtering block page. Based on the exhibits, what is the possible cause of the issue?. The web rating override configuration is incorrect. The web filter profile feature set is configured incorrectly. For www.facebook.com, the URL filter action is incorrect. The firewall policy inspection mode is incorrect. Based on this partial configuration, what are the two possible outcomes when FortiGate enters conserve mode? (Choose two.). FortiGate drops new sessions requiring inspection. Administrators cannot change the configuration. Administrators must restart FortiGate to allow new sessions. FortiGate skips quarantine actions. Refer to the exhibit, which shows an SD-WAN zone configuration on the FortiGate GUI. Based on the exhibit, which statement is true?. The virtual-wan-link and overlay zones can be deleted. The Underlay zone contains no member. The Underlay zone is the zone by default. port2 and port3 are not assigned to a zone. Refer to the exhibits. An administrator has observed the performance status outputs on an HA cluster for 55 seconds. Which FortiGate is the primary?. HQ-NGFW-1 with the parameter memory-failover-flip-timeout setting. HQ-NGFW-1 with the parameter override setting. HQ-NGFW-2 with the parameter priority setting. HQ-NGFW-2 with the parameter memory-failover-threshold setting. Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. Which IP address will be used to source NAT (SNAT) the traffic, if the user on HQ-PC-1 (10.0.11.50) pings the IP address of BR-FGT (100.65.1.111)?. 100.65.0.101. 100.65.0.49. 100.65.0.149. 100.65.0.99. Which two statements about the FortiGuard connection are true? (Choose two.). You can configure unreliable protocols to communicate with FortiGuard Server. The weight increases as the number of failed packets rises. FortiGate is using the default port for FortiGuard communication. FortiGate identified the FortiGuard Server using DNS lookup. Refer to the exhibit, which shows a routing table. An administrator wants to create a new static route so the traffic to the subnet 172.20.1.0/24 is routed through port2 only. What are the two criteria that the administrator can use to achieve this objective? (Choose two.). The existing static route through port3 must have the distance set to 11. The new static route must have the priority set to 3. The new static route must have the distance set to 9. The new static route must have the metric set to 1. Based on the routing table shown in the exhibit, which two statements are true? (Choose two.). A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled. A packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled. A packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled. A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled. The FortiGate device HQ-NGFW-1 with the IP address 10.0.13.254 sends logs to the FortiAnalyzer device with the IP address 10.0.13.125. The administrator wants to verify that reliable logging is enabled on HQ-NGFW-1. Which exhibit helps with the verification?. A) FortiAnalyzer "All Logging Devices" dashboard showing HQ-NGFW-1 with Logging Mode "Real Time". B) FortiAnalyzer "All Logging Devices" dashboard (variant of the previous one). C) CLI output of `diagnose sniffer packet any "host 10.0.13.125" 4` showing UDP 514 and psh/ack traffic. D) CLI configuration:. How does FortiExtender connect to FortiSASE in a site-based, remote internet access method?. FortiExtender establishes a secure SSL connection using FortiClient. FortiExtender first connects to a FortiGate LAN extension through a secure web gateway (SWG). FortiExtender uses a Virtual Extensible LAN (VXLAN)-over-IPsec connection. FortiExtender uses the proxy auto-configuration (PAC) file and an explicit web proxy to connect. You have created a web filter profile named restrict media-profile with a daily category usage quota. When you are adding the profile to the firewall policy, the restrict_media-profile is not listed in the available web profile drop down. What could be the reason?. The inspection mode in the firewall policy is not matching with web filter profile feature set. The naming convention used in the web filter profile is restricting it in the firewall policy. The firewall policy is in no-inspection mode instead of deep-inspection. The web filter profile is already referenced in another firewall policy. An administrator wants to form an HA cluster using the FGCP protocol. Which two requirements must the administrator ensure both members fulfill? (Choose two.). They must have the heartbeat interfaces in the same subnet. They must have the same number of configured VDOMs. They must have the same hard drive configuration. They must have the same HA group ID. A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is not part of the expected process?. The DC agent sends login event data directly to FortiGate. The user logs into the windows domain. The collector agent forwards login event data to FortiGate. FortiGate determines user identity based on the IP address in the FSSO list. You have configured an application control profile, set peer-to-peer traffic to Block under the Categories tab, and applied it to the firewall policy. However, your peer-to-peer traffic on known ports is passing through the FortiGate without being blocked. What FortiGate settings should you check to resolve this issue?. Network Protocol Enforcement. FortiGuard category ratings. Replacement Messages for UDP-based Applications. Application and Filter Overrides. A network administrator is reviewing firewall policies in both Interface Pair View and By Sequence View. The policies appear in a different order in each view. Why is the policy order different in these two views?. Policies in Interface Pair View are prioritized by security levels, while By Sequence View strictly follows the administrator's manual ordering. Interface Pair View sorts policies based on matching interfaces, while By Sequence View shows the actual processing order of rules. By Sequence View groups policies based on rule priority, while Interface Pair View always follows the order of traffic logs. The firewall dynamically reorders policies in Interface Pair View based on recent traffic patterns, but By Sequence View remains static. Which two components are part of the secure internet access (SIA) agent-based mode on FortiSASE? (Choose two.). FortiSASE Firewall-as-a-Service (FWaaS). FortiExtender. VPN policies. The proxy auto-configuration (PAC) file. An administrator wanted to configure an IPS sensor to block traffic that triggers the signature set number of times during a specific time period. How can the administrator achieve the objective?. Use IPS filter, rate-mode periodical option. Use IPS packet logging option with periodical filter option. Use IPS signatures, rate-mode periodical option. Use IPS group signatures, set rate-mode 60. What would be the impact of this configuration on FortiGate?. FortiGate will enable strict RPF on all its interfaces and port1 will be exempted from RPF checks. FortiGate will enable strict RPF on all its interfaces and port1 will be enable for asymmetric routing. Port1 will be enabled with flexible RPF, and all other interfaces will be enabled for strict RPF. The global configuration will take precedence and FortiGate will enable strict RPF on all interfaces. When configuring firewall policies which of the following is true regarding the policy ID? (Choose two.). A firewall policy ID identifies the order of policy execution in firewall policies. It is mandatory to provide a policy ID while creating a firewall policy regardless of GUI or CLI. A policy ID cannot be modified once a policy is created. You can create a policy in CLI with policy ID 0. FortiGate is integrated with FortiAnalyzer and FortiManager. When creating a firewall policy, which attribute must an administrator include to enhance functionality and enable log recording on FortiAnalyzer and FortiManager?. Log ID. Sequence ID. Policy ID. Universally Unique Identifier. What are two characteristics of HA cluster heartbeat IP addresses in a FortiGate device? (Choose two.). A change in the heartbeat IP address happens when a FortiGate device joins or leaves the cluster. Heartbeat IP addresses are used to distinguish between cluster members. The heartbeat interface of the primary device in the cluster is always assigned IP address 169.254.0.1. Heartbeat interfaces have virtual IP addresses that are manually assigned. An administrator has configured a dialup IPsec VPN on FortiGate with add-route enabled. However, the static route is not showing in the routing table. Which two statements about this scenario are correct? (Choose two.). The administrator must use a policy route instead of a static route for add-route to work properly. The administrator must enable a dynamic routing protocol on the dialup interface. The administrator must ensure phase 2 is successfully established. The administrator must define the remote network correctly in the phase 2 selectors. Which three statements about SD-WAN performance SLAs are true? (Choose three.). They rely on session loss and jitter. They are applied in a SD-WAN rule lowest cost strategy. They can be measured actively or passively. They monitor the state of the FortiGate device. All the SLA targets can be configured. Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate device. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.11.50?. 10.0.11.254. 100.65.0.101. 100.65.0.200. 100.65.0.102. An administrator wants to address shadow IT visibility challenges and prevent users from sending sensitive files outside the organization without proper approval. Which FortiSASE method should the administrator implement to achieve these goals?. Secure internet access (SIA). Secure SaaS access (SSA). Secure SD-WAN access (SSD-WAN). Secure private access (SPA). An administrator has created a new firewall address to use as the destination for a static route. Why is the administrator not able to select the new address in the Destination field of the new static route?. In the new firewall address, Routing configuration must be enabled. In the new static route, the administrator must first set the interface to port2. In the new static route, the administrator must select Named Address. In the new firewall address, the FQDN address must first be resolved. Refer to the exhibits. You are asked to implement an antivirus profile for files downloaded through FTP, HTTP, and HTTPS. While testing, you are successful with HTTP and FTP protocols, but FortiGate does not block the file download over HTTPS. What could be the cause?. Web filter is not enabled on the firewall policy to complement the antivirus profile. The action on the firewall policy is not set to deny. The feature set in the antivirus profile is not set to Flow-based. The SSL inspection mode in the firewall policy is not deep content Inspection. You are onboarding an agentless, secure web gateway (SWG) endpoint for secure internet access (SIA). What will happen to the user's nonweb traffic?. All the nonweb traffic will bypass FortiSASE. FortiSASE will use Firewall-as-a-Service (FWaaS) to redirect nonweb traffic. The endpoint will use split tunneling to redirect nonweb traffic to FortiSASE. FortiSASE will use SWG to redirect nonweb traffic to FortiExtender. Refer to the exhibit. Why did the FortiGate device drop the packet?. It matched the default implicit firewall policy. It failed the RPF check. It cannot reach the next-hop IP. It matched an explicitly configured firewall policy with the action DENY. You have configured the FortiGate device for FSSO. A user is successful in log-in to windows, but their access to the internet is denied. What should the administrator check first?. The FortiGate FSSO active users list for user's IP address. Whether the user is assigned to the correct AD group. The FortiGate firewall policy settings for SSL decryption. The windows event viewer for failed login attempts. Which two statements are true about an HA cluster? (Choose two.). When sniffing the heartbeat interface, the administrator must see the IP address 169.254.0.2. Link failover triggers a failover if the administrator sets the interface down on the primary device. An HA cluster cannot have both in-band and out-of-band management interfaces at the same time. HA incremental synchronization includes FIB entries and IPsec SAs. An administrator suspects that the Collector Agent is not forwarding login events to FortiGate. What is the most effective troubleshooting step?. Check if TCP port 8000 is open between the collector agent and FortiGate. Verify if FortiGate is set to use LDAP authentication instead of FSSO. Restart the domain controller to refresh authentication services. Verify if DC agent is enabled on the FortiGate. You are configuring FortiAnalyzer on FortiGate. Which step must you take to connect FortiAnalyzer to FortiGate?. Enable disk logging on FortiGate. Authorize FortiGate on FortiAnalyzer. Verify the FortiAnalyzer serial number. Configure UDP port 514 on FortiGate. Refer to the exhibit. A partial cloud topology is shown. You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS for FortiGate CNF policy enforcement for EC2 which path does the EC2 traffic take from the EC2 instance to the internet?. EC2 instance → GWLBe → FortiGate CNF → GWLBe → IGW → internet. EC2 instance → internet gateway (IGW) → gateway load balancer (GWLB) → FortiGate CNF → internet. EC2 instance → GWBL endpoint (GWLBe) → FortiGate CNF → IGW → internet. EC2 instance → FortiGate CNF → GWLB → GWLBe → IGW → internet. Refer to the exhibits. An administrator configured the Web Filter Profile to block access to all social networking sites except Facebook. However, when users try to access Facebook.com, they are redirected to a FortiGuard web filtering block page. Based on the exhibits, which configuration change must the administrator make to allow Facebook while blocking all other social networking sites?. Set the Action as Exempt for www.facebook.com in the Static URL Filter. Set the Social Networking action as warning in the FortiGuard Category Based Filter. Change the type as Simple in the Static URL Filter section. Change the Feature set of Web Filter Profile as Proxy-based. Refer to the exhibits. An administrator configured both members of an HA cluster at the same time. After one week of monitoring, the administrator wants to verify the HA failover performance. How can the administrator force a failover?. The administrator must reset the HA uptime on HQ-NGFW-1. The administrator must set the parameter override to enable on HQ-NGFW-2. The administrator must set the monitored port1 to down on HQ-NGFW-1. The administrator must increase the HA priority on HQ-NGFW-2. What can you conclude from the log shown in the exhibit?. The IPS socket buffer is full and IPs engine needs more memory to create new sessions. The IPs session scan is paused and reevaluating the packet because of a dirty flag. The IPS socket buffer is full and IPS engine cannot decode a packet. The IPS scan is paused by the IPS diagnostic command with bypass mode option 5. Refer to the exhibit showing a debug flow output. Which two conclusions can you make from the debug flow output? (Choose two.). The default gateway is configured on port2. The matching firewall policy denies the traffic. The RPF check fails. The debug flow is for UDP traffic. Which two ways can you view the log messages shown in the exhibit? (Choose two.). By filtering by policy universally unique identifier (UUID) and application name in the log entry. By right clicking the implicit deny policy. Using the FortiGate CLI command diagnose log test. In the Forward Traffic section. An administrator wants to form an HA cluster using the FGCP protocol. Both FortiGate devices are configured with the set override enable command. Arrange the criteria in the order in which the FGCP protocol uses them to elect the primary FortiGate. HA uptime. Connected monitored ports. System uptime. FortiGate serial number. Priority. Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. You cannot access any of the Google applications, but you are able to access www.fortinet.com. What would you do to resolve this issue?. Set the action for Excessive-Bandwidth in the Application and Filter Overrides section to Allow. Set the action for Google in the Application and Filter Overrides section to Monitor. Move up Google in the Application and Filter Overrides section to set its priority to 1. Add *Google*.com to the URL category in the security profile. Refer to the exhibits. You have implemented the application sensor and the corresponding firewall policy as shown in the exhibits. You can access the Gmail chat application, but there is no log generated under security logs. Which two actions would you take to resolve the issue? (Choose two.). Add *Google*.com to the URL category in the security profile. Change the Inspection mode to Flow-based. Move up Google in the Application and Filter Overrides section to set its priority to 1. Set the action for Gmail_Chat in the Application and Filter Overrides section to Monitor. Set SSL inspection to deep-inspection. |




