Pass the Fortinet NSE EMEA-Advanced-Support Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which FortiGate feature allows for dynamic routing protocol updates to be propagated through an IPsec VPN tunnel?

Options:

A.

Auto Discovery VPN (ADVPN)


B.

Dynamic Routing Gateway


C.

Virtual Routing and Forwarding (VRF)


D.

Route-based VPN


Expert Solution
Questions # 2:

In FortiGate, what is the purpose of the ‘set webfilter-profile’ command in a firewall policy?

Options:

A.

Applies a web filtering profile to block or allow URLs


B.

Enables deep packet inspection for web traffic


C.

Configures the web proxy settings


D.

Sets the web server authentication profile


Expert Solution
Questions # 3:

Which statement is true about IPsec VPNs and SSL VPNs?

Options:

A.

SSL VPN creates a HTTPS connection. IPsec does not


B.

Both SSL VPNs and IPsec VPNs are standard protocols


C.

Either a SSL VPN or an IPsec VPN can be established between an end-user workstation and a FortiGate device


D.

All of the above


Expert Solution
Questions # 4:

Which term refers to the OSPF router that connects area 0 to a nonbackbone area?

Options:

A.

area boundary router


B.

area border router


C.

autonomous system boundary router


D.

backbone router


Expert Solution
Questions # 5:

What is the purpose of FortiGate’s ‘FortiGuard’ service in security profiles?

Options:

A.

Provides real-time threat intelligence updates


B.

Enables local storage of security logs


C.

Configures VPN tunnel encryption


D.

Manages HA cluster synchronization


Expert Solution
Questions # 6:

What is the role of the FortiGate ‘set srcintf’ command in a firewall policy?

Options:

A.

Specifies the source interface for traffic matching


B.

Defines the destination interface for traffic


C.

Sets the source IP address range


D.

Configures the source NAT interface


Expert Solution
Questions # 7:

Link aggregation allows network devices to________

Options:

A.

Increase bandwidth of an interface


B.

Increase bandwidth by binding physical interfaces into a single channel


C.

Restrict the bandwidth


D.

None of the above


Expert Solution
Questions # 8:

In Active FTP who sends the PORT command?

Options:

A.

The FTP Client


B.

The FTP Server


C.

Both


D.

There is no PORT command in Active FTP


Expert Solution
Questions # 9:

Which of the below technology(ies) could reduce CPU load and memory utilization used by an IPS engine?

Options:

A.

IPS does not compare traffic to each signature individually. Instead it compiles them into a decision tree


B.

Using IPS sensors and IPS filter to determine which traffic should be examined for which signatures, instead of examine network traffic for all signatures


C.

Using multiple engines, aligned with load balancing technologies like Turbo that uses round robin algorithms to dispatch traffic up to specific IPS engine


D.

Using regular instead of extended database, to reduce memory footprint


E.

All of the above


Expert Solution
Questions # 10:

Which parts of the IKE protocol below are responsible for authenticating the User (username/password) of a dialup IPsec tunnel? (Check all correct answers)

Options:

A.

IKEv1 phase2


B.

IKEv1 Xauth


C.

IKEv2 EAP


D.

IKEv1 phase1


E.

IKEv2 SA_INIT


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions