لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
Which statement about firewall policy NAT is true?
A. DNAT is not supported
B. DNAT can automatically apply to multiple firewall policies, based on DNAT rules
C. You must configure SNAT for each firewall policy
D. SNAT can automatically apply to multiple firewall policies, based on SNAT rules
عرض الإجابة
اجابة صحيحة: C
السؤال #2
A new administrator is configuring FSSO authentication on FortiGate using DC Agent Mode. Which step is NOT part of the expected process?
A. The DC agent sends login event data directly to FortiGate
B. The user logs into the windows domain
C. The collector agent forwards login event data to FortiGate
D. FortiGate determines user identity based on the IP address in the FSSO list
عرض الإجابة
اجابة صحيحة: C
السؤال #3
What must you configure to enable proxy-based TCP session failover?
A. You must configure ha-configuration-sync under configure system ha
B. You do not need to configure anything because all TCP sessions are automatically failed over
C. You must configure session-pickup-enable under configure system ha
D. You must configure session-pickup-connectionless enable under configure system ha
عرض الإجابة
اجابة صحيحة: C
السؤال #4
You have created a web filter profile named restrict_media - profile with a daily category usage quota. When you are adding the profile to the firewall policy, the restrict_media - profile is not listed in the available web profile drop down. What could be the reason?
A. The firewall policy is in no - inspection mode instead of deep - inspection
B. The inspection mode in the firewall policy is not matching with web filter profile feature set
C. The web filter profile is already referenced in another firewall policy
D. The naming convention used in the web filter profile is restricting it in the firewall policy
عرض الإجابة
اجابة صحيحة: B
السؤال #5
Refer to the exhibit. Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP .Login.Failed signature to the IPS sensor profile?
A. Traffic matching the signature will be silently dropped and logged
B. The signature setting uses a custom rating threshold
C. The signature setting includes a group of other signatures
D. Traffic matching the signature will be allowed and logged
عرض الإجابة
اجابة صحيحة: A
السؤال #6
Which statement correctly describes the use of reliable logging on FortiGate?
A. Reliable logging is enabled by default in all configuration scenarios
B. Reliable logging is required to encrypt the transmission of logs
C. Reliable logging can be configured only using the CL
D. Reliable logging prevents the loss of logs when the local disk is full
عرض الإجابة
اجابة صحيحة: B
السؤال #7
Which two settings must you configure when FortiGate is being deployed as a root FortiGate in a Security Fabric topology? (Choose two.)
A. FortiManager IP addresscorrect
B. FortiAnalyzer IP addresscorrect
C. Pre-authorize downstream FortiGate devices
D. Fabric namecorrect
عرض الإجابة
اجابة صحيحة: ABD
السؤال #8
Which two statements about incoming and outgoing interfaces in firewall policies are true? (Choose two.)
A. Only the "any" interface can be chosen as an incoming interface
B. An incoming interface is mandatory in a firewall policy, but an outgoing interface is optional
C. Multiple interfaces can be selected as incoming and outgoing interfaces
D. A zone can be chosen as the outgoing interface
عرض الإجابة
اجابة صحيحة: ACD
السؤال #9
Refer to the exhibits. The exhibits show the SSL and authentication policy (Exhibit A) and the security policy (Exhibit B) for Facebook. Users are given access to the Facebook web application. They can play video content hosted on Facebook, but they are unable to leave reactions on videos or other types of posts. Which part of the policy configuration must you change to resolve the issue?
A. Force access to Facebook using the HTTP service
B. Make the SSL inspection a deep content inspection
C. Add Facebook in the URL category in the security policy
D. Get the additional application signatures required to add to the security policy
عرض الإجابة
اجابة صحيحة: B
السؤال #10
A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service. Which type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
A. Pre-shared key
B. Dialup usercorrect
C. Dynamic DNS
D. Static IP address
عرض الإجابة
اجابة صحيحة: B
السؤال #11
Refer to the exhibits. Exhibit A shows system performance output. Exhibit B shows a FortiGate configured with the default configuration of high memory usage thresholds. Based on the system performance output, which two results are correct? (Choose two.)
A. FortiGate will start sending all files to FortiSandbox for inspection
B. FortiGate has entered conserve mode
C. Administrators cannot change the configuration
D. Administrators can access FortiGate only through the console port
عرض الإجابة
اجابة صحيحة: ABC
السؤال #12
Which timeout setting can be responsible for deleting SSL VPN associated sessions?
A. SSL VPN idle-timeoutcorrect
B. SSL VPN http-request-body-timeout
C. SSL VPN login-timeout
D. SSL VPN dtls-hello-timeout
عرض الإجابة
اجابة صحيحة: A
السؤال #13
Refer to the exhibits. An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW). What must the administrator do to synchronize the address object?
A. Change the csf setting on ISFW (downstream) to set configuration-sync local
B. Change the csf setting on ISFW (downstream) to set authorization-request-type certificate
C. Change the csf setting on both devices to set downstream-access enable
D. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default
عرض الإجابة
اجابة صحيحة: C
السؤال #14
Refer to the exhibits. The exhibits contain a network diagram, and virtual IP, IP pool, and firewall policies configuration information. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The first firewall policy has NAT enabled using IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address
A. 10
B. 10
C. 10
D. 10
عرض الإجابة
اجابة صحيحة: D

View The Updated Fortinet Exam Questions

SPOTO Provides 100% Real Fortinet Exam Questions for You to Pass Your Fortinet Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف: