7.0 Flashcards
(172 cards)
Which two statements about FortiGate FSSO agentless polling mode are true? (Choose two.)
FortiGate uses the SMB protocol to read the event viewer logs from the DCs.
FortiGate directs the collector agent to use a remote LDAP server.
FortiGuard categories can be overridden and defined in different categories. To create a web rating
override for example.com home page, the override must be configured using a specific syntax.
Which two syntaxes are correct to configure web rating for the home page? (Choose two.)
www.example.com
example.com
Refer to the exhibits to view the firewall policy (Exhibit A) and the antivirus profile (Exhibit B).
Which statement is correct if a user is unable to receive a block replacement message when
downloading an infected file for the first time?
The flow-based inspection is used, which resets the last packet to the user.
Which three options are the remote log storage options you can configure on FortiGate? (Choose
three.)
FortiSIEM
FortiAnalyzer
FortiCloud
Which statement correctly describes NetAPI polling mode for the FSSO collector agent?
The NetSession Enum function is used to track user logouts.
Refer to the exhibit.
An administrator is running a sniffer command as shown in the exhibit.
Which three pieces of information are included in the sniffer output? (Choose three.)
Interface name
IP header
Packet payload
Refer to the exhibit.
The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of
diagnose sys virtual-wan-link health-check.
Which interface will be selected as an outgoing interface?
port1
An administrator does not want to report the logon events of service accounts to FortiGate. What
setting on the collector agent is required to achieve this?
Add user accounts to the Ignore User List.
Refer to the exhibit
The global settings on a FortiGate device must be changed to align with company security policies.
What does the Administrator account need to access the FortiGate global settings?
Change Administrator profile
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true
about the policy list view?
Interface Pair view will be disabled
Refer to the exhibit.
Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)
port1 is a native VLAN
port1-vlan and port2-vlan1 can be assigned in the same VDOM or to different VDOMs
A network administrator wants to set up redundant IPsec VPN tunnels on FortiGate by using two
IPsec VPN tunnels and static routes.
* All traffic must be routed through the primary tunnel when both tunnels are up
* The secondary tunnel must be used only if the primary tunnel goes down
* In addition, FortiGate should be able to detect a dead tunnel to speed up tunnel failover
Which two key configuration changes are needed on FortiGate to meet the design requirements?
(Choose two)
Enable Dead Peer Detection
Configure a lower distance on the static route for the primary tunnel, and a higher distance on the
static route for the secondary tunnel
Refer to the exhibit.
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)
FortiGate SN FGVM010000065036 HA uptime has been reset.
FortiGate SN FGVM010000064692 has the higher HA priority.
Refer to the exhibits.
Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default
configuration of high memory usage thresholds. Based on the system performance output, which
two statements are correct? (Choose two.)
FortiGate has entered conserve mode.
Administrators cannot change the configuration.
An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting
in both sites has been configured as Static IP Address. For site A, the local quick mode selector is
192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
192.168.2.0/24
Refer to the exhibits.
The SSL VPN connection fails when a user attempts to connect to it. What should the user do to
successfully connect to SSL VPN?
Change the SSL VPN port on the client.
Which two statements about SSL VPN between two FortiGate devices are true? (Choose two.)
The client FortiGate uses the SSL VPN tunnel interface type to connect SSL VPN.
Server FortiGate requires a CA certificate to verify the client FortiGate certificate.
Refer to the exhibit.
The Root and To_Internet VDOMs are configured in NAT mode. The DMZ and Local VDOMs are
configured in transparent mode.
The Root VDOM is the management VDOM. The To_Internet VDOM allows LAN users to access the
internet. The To_Internet VDOM is the only VDOM with internet access and is directly connected to
ISP modem.
With this configuration, which statement is true?
Inter-VDOM links are required to allow traffic between the Local and Root VDOMs.
Refer to the exhibits.
An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security
fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?
Change the csf setting on Local-FortiGate (root) to sec configuration-sync local.
Refer to the exhibit.
Which contains a session list output. Based on the information shown in the exhibit, which statement
is true?
One-to-one NAT IP pool is used in the firewall policy.
Which two statements are correct about SLA targets? (Choose two.)
SLA targets are optional
SLA targets are used only when referenced by an SD-WAN rule.
Refer to the exhibit.
Which contains a session diagnostic output. Which statement is true about the session diagnostic
output?
The session is in SYN_SENT state
Which statement is correct regarding the inspection of some of the services available by web
applications embedded in third-party websites?
FortiGate can inspect sub-application traffic regardless where it was originated.
Which engine handles application control traffic on the next-generation firewall (NGFW) FortiGate?
Intrusion prevention system engine