Which statement about FortiGuard services for FortiGate is true? The web filtering database is downloaded locally on FortiGate Antivirus signatures are downloaded locally on FortiGate FortiGate downloads IPS updates using UDP port 53 or 8888. FortiAnalyzer can be configured as a local FDN to provide antivirus and IPS updates.
Which of the following route attributes must be equal for static routes to be eligible for equal cost multipath (ECMP) routing? (Choose two.) Priority Metric Distance Cost.
Based on this output, which statements are correct? (Choose two.)
View the exhibit. The all VDOM is not synchronized between the primary and secondary FortiGate devices. The root VDOM is not synchronized between the primary and secondary FortiGate devices The global configuration is synchronized between the primary and secondary FortiGate devices. The FortiGate devices have three VDOMs.
Which statement is true regarding the policy ID number of a firewall policy? Defines the order in which rules are processed. Represents the number of objects used in the firewall policy. Required to modify a firewall policy using the CLI. Changes when firewall policies are reordered.
An administrator wants to block HTTP uploads. Examine the exhibit, which contains the proxy address created for that purpose. Where must the proxy address be used? As the source in a firewall policy As the source in a proxy policy. As the destination in a firewall policy. As the destination in a proxy policy.
Which statement is true regarding SSL VPN timers? (Choose two.) Allow to mitigate DoS attacks from partial HTTP requests. SSL VPN settings do not have customizable timers. Disconnect idle SSL VPN users when a firewall policy authentication timeout occurs. Prevent SSL VPN users from being logged out because of high network latency.
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA? The public key of the web server certificate must be installed on the browser. The web-server certificate must be installed on the browser.
The CA certificate that signed the web-server certificate must be installed on the browser The private key of the CA certificate that signed the browser certificate must be installed on the browser.
When using SD-WAN, how do you configure the next-hop gateway address for a member interface so that FortiGate can forward Internet traffic? It must be configured in a static route using the sdwan virtual interface. It must be provided in the SD-WAN member interface configuration. It must be configured in a policy-route using the sdwan virtual interface. It must be learned automatically through a dynamic routing protocol.
Which of the following services can be inspected by the DLP profile? (Choose three.) NFS FTP IMAP CIFS HTTP-POST.
Which of the following statements describe WMI polling mode for the FSSO collector agent? (Choose two.) The NetSessionEnum function is used to track user logoffs. WMI polling can increase bandwidth usage in large networks The collector agent uses a Windows API to query DCs for user logins. The collector agent do not need to search any security event logs.
You are configuring the root FortiGate to implement the security fabric. You are configuring port10 to communicate with a downstream FortiGate. View the default
Edit Interface in the exhibit below:
When configuring the root FortiGate to communicate with a downstream FortiGate, which settings are required to be configured? (Choose two.) Device detection enabled. Administrative Access: FortiTelemetry. IP/Network Mask. Role: Security Fabric.
What FortiGate components are tested during the hardware test? (Choose three.) Administrative access HA heartbeat CPU Hard disk Network interfaces.
Which statements correctly describe transparent mode operation? (Choose three.)
All interfaces of the transparent mode FortiGate device must be on different IP subnets. Ethernet packets are forwarded based on destination MAC addresses, not IP addresses. The transparent FortiGate is visible to network hosts in an IP traceroute. It permits inline traffic inspection and firewalling without changing the IP scheme of the network. FortiGate acts as transparent bridge and forwards traffic at Layer 2.
Which of the following statements are correct? (Choose two.)
View the exhibit. This setup requires at least two firewall policies with the action set to IPsec. Dead peer detection must be disabled to support this type of IPsec setup The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down. This is a redundant IPsec setup.
Which one of the following processes is involved in updating IPS from FortiGuard? FortiGate IPS update requests are sent using UDP port 443. Protocol decoder update requests are sent to service.fortiguard.net. IPS signature update requests are sent to update.fortiguard.net. IPS engine updates can only be obtained using push updates.
How does FortiGate select the central SNAT policy that is applied to a TCP session? It selects the SNAT policy specified in the configuration of the outgoing interface. It selects the first matching central SNAT policy, reviewing from top to bottom. It selects the central SNAT policy with the lowest priority It selects the SNAT policy specified in the configuration of the firewall policy that matches the traffic.
Which of the following conditions are required for establishing an IPSec VPN between two FortiGate devices? (Choose two.) If XAuth is enabled as a server in one peer, it must be enabled as a client in the other peer If the VPN is configured as route-based, there must be at least one firewall policy with the action set to IPSec. If the VPN is configured as DialUp User in one peer, it must be configured as either Static IP Address or Dynamic DNS in the other peer. If the VPN is configured as a policy-based in one peer, it must also be configured as policy-based in the other peer.
Which of the following statements about converse mode are true? (Choose two.) FortiGate stops sending files to FortiSandbox for inspection. FortiGate stops doing RPF checks over incoming packets. Administrators cannot change the configuration. Administrators can access the FortiGate only through the console port.
Why is the administrator getting the error shown in the exhibit?
View the exhibit. The administrator must first enter the command edit global The administrator admin does not have the privileges required to configure global settings. The global settings cannot be configured from the root VDOM context.
The command config system global does not exist in FortiGate.
Examine the network diagram and the existing FGTI routing table shown in the exhibit, and then answer the following question:
Since the change, the new static route is not showing up in the routing table. Given the information provided, which of the following describes the cause of this
problem? The new route’s destination subnet overlaps an existing route. The new route’s Distance value should be higher than 10. The Gateway IP address is not in the same subnet as port1. The Priority is 0, which means that this route will remain inactive.
Which configuration objects can be selected for the Source field of a firewall policy? (Choose two.) Firewall service User or user group IP Pool FQDN address.
Which users and user groups are allowed access to the network through captive portal?
View the exhibit. Users and groups defined in the firewall policy Only individual users – not groups – defined in the captive portal configuration Groups defined in the captive portal configuration All users.
NGFW mode allows policy-based configuration for most inspection rules. Which security profile’s configuration does not change when you enable policy-based inspection? Web filtering Antivirus Web proxy Application control.
During the digital verification process, comparing the original and fresh hash results satisfies which security requirement? Authentication. Data integrity. Non-repudiation. Signature verification.
An administration wants to throttle the total volume of SMTP sessions to their email server. Which of the following DoS sensors can be used to achieve this? tcp_port_scan ip_dst_session udp_flood ip_src_session.
Why must you use aggressive mode when a local FortiGate IPSec gateway hosts multiple dialup tunnels? In aggressive mode, the remote peers are able to provide their peer IDs in the first message. FortiGate is able to handle NATed connections only in aggressive mode. FortiClient only supports aggressive mode. Main mode does not support XAuth for user authentication.
Why did the FortiGate drop the packet?
Examine this output from a debug flow: The next-hop IP address is unreachable. It failed the RPF check. It matched an explicitly configured firewall policy with the action DENY. It matched the default implicit firewall policy.
What should be done next to troubleshoot the problem?
View the exhibit: Run a sniffer in the web server Execute another sniffer in the FortiGate, this time with the filter “host 10.0.1.10”. Capture the traffic using an external sniffer connected to port1 Execute a debug flow.
Which of the following statements about policy-based IPsec tunnels are true? (Choose two.) They can be configured in both NAT/Route and transparent operation modes. They support L2TP-over-IPsec. They require two firewall policies: one for each directions of traffic flow. They support GRE-over-IPsec.
An employee connects to the https://example.com on the Internet using a web browser. The web server’s certificate was signed by a private internal CA. The
FortiGate that is inspecting this traffic is configured for full SSL inspection.
This exhibit shows the configuration settings for the SSL/SSH inspection profile that is applied to the policy that is invoked in this instance. All other settings are set
to defaults. No certificates have been imported into FortiGate. View the exhibit and answer the question that follows.
Which certificate is presented to the employee’s web browser? The web server’s certificate The user’s personal certificate signed by a private internal CA. A certificate signed by Fortinet_CA_SSL. A certificate signed by Fortinet_CA_Untrusted.
An administrator is attempting to allow access to https://fortinet.com through a firewall policy that is configured with a web filter and an SSL inspection profile configured for deep inspection. Which of the following are possible actions to eliminate the certificate error generated by deep inspection? (Choose two.) Implement firewall authentication for all users that need access to fortinet.com. Manually install the FortiGate deep inspection certificate as a trusted CA Configure fortinet.com access to bypass the IPS engine. Configure an SSL-inspection exemption for fortinet.com.
How does FortiGate verify the login credentials of a remote LDAP user? FortiGate regenerates the algorithm based on the login credentials and compares it to the algorithm stored on the LDAP server. FortiGate sends the user-entered credentials to the LDAP server for authentication. FortiGate queries the LDAP server for credentials. FortiGate queries its own database for credentials.
Which action can be applied to each filter in the application control profile? Block, monitor, warning, and quarantine Allow, monitor, block and learn Allow, block, authenticate, and warning Allow, monitor, block, and quarantine.
Based on the configuration shown in the exhibit, what statements about application control behavior are true? (Choose two.)
View the exhibit. Access to all unknown applications will be allowed. Access to browser-based Social.Media applications will be blocked. Access to mobile social media applications will be blocked. Access to all applications in Social.Media category will be blocked.
HTTP Public Key Pinning (HPKP) can be an obstacle to implementing full SSL inspection. What solutions could resolve this problem? (Choose two.) Enable Allow Invalid SSL Certificates for the relevant security profile. Change web browsers to one that does not support HPKP Exempt those web sites that use HPKP from full SSL inspection Install the CA certificate (that is required to verify the web server certificate) stores of users’ computers.
What does this raw log indicate? (Choose two.)
View the exhibit. FortiGate blocked the traffic type indicates that a security event was recorded 10.0.1.20 is the IP address for lavito.tk. policyid indicates that traffic went through the IPS firewall policy.
Which of the following statements are true when using WPAD with the DHCP discovery method? (Choose two.) If the DHCP method fails, browsers will try the DNS method. The browser needs to be preconfigured with the DHCP server’s IP address The browser sends a DHCPONFORM request to the DHCP server. The DHCP server provides the PAC file for download.
Examine the routing database shown in the exhibit, and then answer the following question:
Which of the following statements are correct? (Choose two.) The port3 default route has the highest distance. The port3 default route has the lowest metric. There will be eight routes active in the routing table. The port1 and port2 default routes are active in the routing table.
If traffic matches a DLP filter with the action set to Quarantine IP Address, what action does FortiGate take? It notifies the administrator by sending an email. It provides a DLP block replacement page with a link to download the file. It blocks all future traffic for that IP address for a configured interval. It archives the data for that IP address.
Which of the following statements about the FSSO collector agent timers is true? The workstation verify interval is used to periodically check of a workstation is still a domain member. The IP address change verify interval monitors the server IP address where the collector agent is installed, and the updates the collector agent configuration if it changes. The user group cache expiry is used to age out the monitored groups. The dead entry timeout interval is used to age out entries with an unverified status.
A FortiGate device has multiple VDOMs. Which statement about an administrator account configured with the default prof_admin profile is true? It can create administrator accounts with access to the same VDOM. It cannot have access to more than one VDOM. It can reset the password for the admin account. It can upgrade the firmware on the FortiGate device.
Which of the following features is supported by web filter in flow-based inspection mode with NGFW mode set to profile-based? FortiGuard Quotas Static URL Search engines Rating option.
The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port2) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0.1.10/24?
Examine the exhibit, which contains a virtual IP and firewall policy configuration. 10.200.1.10 Any available IP address in the WAN (port1) subnet 10.200.1.0/24 10.200.1.1 10.0.1.254.
By default, when logging to disk, when does FortiGate delete logs? 30 days 1 year Never 7 days.
Examine the exhibit, which contains a session diagnostic output.
Which of the following statements about the session diagnostic output is true? The session is in ESTABLISHED state. The session is in LISTEN state. The session is in TIME_WAIT state. The session is in CLOSE_WAIT state.
Which of the following statements about backing up logs from the CLI and downloading logs from the GUI are true? (Choose two.) Log downloads from the GUI are limited to the current filter view Log backups from the CLI cannot be restored to another FortiGate. Log backups from the CLI can be configured to upload to FTP as a scheduled time Log downloads from the GUI are stored as LZ4 compressed files.
Examine the network diagram shown in the exhibit, then answer the following question:
Which one of the following routes is the best candidate route for FGT1 to route traffic from the Workstation to the Web server? 172.16.0.0/16 [50/0] via 10.4.200.2, port2 [5/0] 0.0.0.0/0 [20/0] via 10.4.200.2, port2 10.4.200.0/30 is directly connected, port2 172.16.32.0/24 is directly connected, port1.
A team manager has decided that while some members of the team need access to particular website, the majority of the team does not. Which configuration option is the most effective option to support this request? Implement a web filter category override for the specified website. Implement web filter authentication for the specified website Implement web filter quotas for the specified website. Implement DNS filter for the specified website.
You have tasked to design a new IPsec deployment with the following criteria:
- There are two HQ sues that all satellite offices must connect to
- The satellite offices do not need to communicate directly with other satellite offices
- No dynamic routing will be used
- The design should minimize the number of tunnels being configured.
Which topology should be used to satisfy all of the requirements? Partial mesh Hub-and-spoke Fully meshed Redundant.
Which of the following statements is true regarding SSL VPN settings for an SSL VPN portal? By default, FortiGate uses WINS servers to resolve names. By default, the SSL VPN portal requires the installation of a client’s certificate By default, split tunneling is enabled. By default, the admin GUI and SSL VPN portal use the same HTTPS port.
An administrator has configured the following settings:
What does the configuration do? (Choose two.) Reduces the amount of logs generated by denied traffic. Enforces device detection on all interfaces for 30 minutes. Blocks denied users for 30 minutes. Creates a session for traffic being denied.
An administrator observes that the port1 interface cannot be configured with an IP address. What can be the reasons for that? (Choose three.) The interface has been configured for one-arm sniffer. The interface is a member of a virtual wire pair. The operation mode is transparent. The interface is a member of a zone. Captive portal is enabled in the interface.
Which is the correct description of a hash result as it relates to digital certificates? A unique value used to verify the input data An output value that is used to identify the person or deduce that authored the input data An obfuscation used to mask the input data An encrypted output value used to safe-guard the input data.
Examine the exhibit, which shows the partial output of an IKE real-time debug.
Which of the following statement about the output is true? The VPN is configured to use pre-shared key authentication Extended authentication (XAuth) was successful. Remote is the host name of the remote IPsec peer Phase 1 went down.
Examine the network diagram shown in the exhibit, and then answer the following question:
A firewall administrator must configure equal cost multipath (ECMP) routing on FGT1 to ensure both port1 and port3 links are used at the same time for all traffic destined for 172.20.2.0/24. Which of the following static routes will satisfy this requirement on FGT1? (Choose two.) 172.20.2.0/24 (1/0) via 10.10.1.2, port1 [0/0] 172.20.2.0/24 (25/0) via 10.10.3.2, port3 [5/0] 172.20.2.0/24 (1/150) via 10.10.3.2, port3 [10/0] 172.20.2.0/24 (1/150) via 10.30.3.2, port3 [10/0].
Examine this FortiGate configuration:
Based on the diagnostic outputs above, how is the FortiGate handling the traffic for new sessions that require inspection? . It is allowed, but with no inspection It is allowed and inspected as long as the inspection is flow based It is dropped It is allowed and inspected, as long as the only inspection required is antivirus.
When using WPAD DNS method, which FQDN format do browsers use to query the DNS server? srv_proxy.<local-domain>/wpad.dat srv_tcp.wpad.<local-domain> wpad.<local-domain> proxy.<local-domain>.wpad.
Examine the IPS sensor configuration shown in the exhibit, and then answer the question below.
An administrator has configured the WINDOS_SERVERS IPS sensor in an attempt to determine
whether the influx of HTTPS traffic is an attack attempt or not. After applying the IPS sensor, FortiGate is still not generating any IPS logs for the HTTPS traffic.
What is a possible reason for this? The IPS filter is missing the Protocol: HTTPS option. The HTTPS signatures have not been added to the sensor A DoS policy should be used, instead of an IPS sensor. A DoS policy should be used, instead of an IPS sensor. The firewall policy is not using a full SSL inspection profile.
What types of traffic and attacks can be blocked by a web application firewall (WAF) profile? (Choose three.) Traffic to botnetservers Traffic to inappropriate web sites Server information disclosure attacks Credit card data leaks SQL injection attacks.
Examine this PAC file configuration.
Which of the following statements are true? (Choose two.) Browsers can be configured to retrieve this PAC file from the FortiGate Any web request to the 172.25.120.0/24 subnet is allowed to bypass the proxy. All requests not made to Fortinet.com or the 172.25.120.0/24 subnet, have to go through altproxy.corp.com: 8060. Any web request fortinet.com is allowed to bypass the proxy.
Which statements best describe auto discovery VPN (ADVPN). (Choose two.) It requires the use of dynamic routing protocols so that spokes can learn the routes to other spokes. ADVPN is only supported with IKEv2. Tunnels are negotiated dynamically between spokes. Every spoke requires a static tunnel to be configured to other spokes so that phase 1 and phase 2 proposals are defined in advance.
An administrator needs to create an SSL-VPN connection for accessing an internal server using the bookmark Port Forward. What step is required for this configuration? Configure an SSL VPN realm for clients to use the port forward bookmark.
Configure the client application to forward IP traffic through FortiClient. Configure the virtual IP address to be assigned t the SSL VPN users. Configure the client application to forward IP traffic to a Java applet proxy.
Which statements are true regarding firewall policy NAT using the outgoing interface IP address with fixed port disabled? (Choose two.) This is known as many-to-one NAT Source IP is translated to the outgoing interface IP. Connections are tracked using source port and source MAC address Port address translation is not used.