Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Network Security Expert NSE8_812 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit, which shows a FortiGate configuration snippet.

Question # 1

A customer in Costa Rica has a FortiGate with SD-WAN configured to use a VPN connection to the United States to browse the internet using a public IP from that country. They would like to enable the SD-WAN rule using a webhook.

Which configuration must be added to the FortiGate, and which type of HTTP request must be used to accomplish this? (Choose two.)

Options:

A.

NSE8_812 Question 1 Option 1


B.

1


C.

1


D.

1


Expert Solution
Questions # 2:

Refer to the exhibits, which show a firewall policy configuration and a network topology.

Question # 2

An administrator has configured an inbound SSL inspection profile on a FortiGate device (FG-1) that is protecting a data center hosting multiple web pages-Given the scenario shown in the exhibits, which certificate will FortiGate use to handle requests to xyz.com?

Options:

A.

FortiGate will fall-back to the default Fortinet_CA_SSL certificate.


B.

FortiGate will reject the connection since no certificate is defined.


C.

FortiGate will use the Fortinet_CA_Untrusted certificate for the untrusted connection,


D.

FortiGate will use the first certificate in the server-cert list—the abc.com certificate


Expert Solution
Questions # 3:

Refer to the exhibit, which shows a VPN topology.

Question # 3

The device IP 10.1.100.40 downloads a file from the FTP server IP 192.168.4.50

Referring to the exhibit, what will be the traffic flow behavior if ADVPN is configured in this environment?

Options:

A.

All the session traffic will pass through the Hub


B.

The TCP port 21 must be allowed on the NAT Device2


C.

ADVPN is not supported when spokes are behind NAT


D.

Spoke1 will establish an ADVPN shortcut to Spoke2


Expert Solution
Questions # 4:

An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the OCSP server.

Part of the FortiGate configuration is shown below:

Question # 4

Based on this configuration, which authentication scenario will FortiGate deny?

Options:

A.

The user certificate does not contain the OCSP URL.


B.

FortiAuthenticator responds to an OCSP request that the user certificate authority is untrusted.


C.

FortiAuthenticator responds to an OCSP request that the user certificate status is unknown.


Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

A FortiWeb appliance is configured for load balancing web sessions to internal web servers. The Server Pool is configured as shown in the exhibit.

How will the sessions be load balanced between server 1 and server 2 during normal operation?

Options:

A.

Server 1 will receive 25% of the sessions, Server 2 will receive 75% of the sessions


B.

Server 1 will receive 20% of the sessions, Server 2 will receive 66.6% of the sessions


C.

Server 1 will receive 33.3% of the sessions, Server 2 will receive 66 6% of the sessions


D.

Server 1 will receive 0% of the sessions Server 2 will receive 100% of the sessions


Expert Solution
Questions # 6:

Which two statements about bounce address tagging and verification (BATV) on FortiMail are true? (Choose two.)

Options:

A.

You must publish the BATV public key as a DNS TXT record.


B.

Emails with an empty sender address will be subjected to bounce verification.


C.

FortiMail will insert the BATV tag to the sender address in the envelope.


D.

BATV will use symmetric keys to verify the bounce address tag.


Expert Solution
Questions # 7:

You are migrating the branches of a customer to FortiGate devices. They require independent routing tables on the LAN side of the network.

After reviewing the design, you notice the firewall will have many BGP sessions as you have two data centers (DC) and two ISPs per DC while each branch is using at least 10 internal segments.

Based on this scenario, what would you suggest as the more efficient solution, considering that in the future the number of internal segments, DCs or internet links per DC will increase?

Options:

A.

No change in design is needed as even small FortiGate devices have a large memory capacity.


B.

Acquire a FortiGate model with more capacity, considering the next 5 years growth.


C.

Implement network-id, neighbor-group and increase the advertisement-interval


D.

Redesign the SD-WAN deployment to only use a single VPN tunnel and segment traffic using VRFs on BGP


Expert Solution
Questions # 8:

Refer to the exhibit.

Question # 8

A customer reports that they are not able to reach subnet 10.10.10.0/24 from their FortiGate device.

Based on the exhibit, what should you do to correct the situation?

Options:

A.

Enable iBGP multipath


B.

Enable recursive resolution for BGP routes


C.

Enable next-hop-self feature


D.

Enable additional-path feature


Expert Solution
Questions # 9:

Which two statements are correct on a FortiGate using the FortiGuard Outbreak Protection Service (VOS)? (Choose two.)

Options:

A.

The FortiGuard VOS can be used only with proxy-base policy inspections.


B.

If third-party AV database returns a match the scanned file is deemed to be malicious.


C.

The antivirus database queries FortiGuard with the hash of a scanned file


D.

The AV engine scan must be enabled to use the FortiGuard VOS feature


E.

The hash signatures are obtained from the FortiGuard Global Threat Intelligence database.


Expert Solution
Questions # 10:

Review the following FortiGate-6000 configuration excerpt:

Question # 10

Based on the configuration, which statement is correct regarding SNAT source port partitioning behavior?

Options:

A.

It dynamically distributes SNAT source ports to operating FPCs or FPMs.


B.

It is the default SNAT configuration and preserves active sessions when an FPC or FPM goes down.


C.

It statically distributes SNAT source ports to operating FPCs or FPMs


D.

It equally distributes SNAT source ports across chassis slots.


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions