Pass the Fortinet Fortinet Network Security Expert NSE8_812 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

You are designing a setup where the FortiGate device is connected to two upstream ISPs using BGP. Part of the requirement is that you must be able to refresh the route advertisements manually without disconnecting the BGP neighborships.

Which feature must you enable on the BGP neighbors to accomplish this goal?

Options:

A.

Synchronization


B.

Deterministic-med


C.

Graceful-restart


D.

Soft-reconfiguration


Expert Solution
Questions # 2:

Refer to the exhibits.

Question # 2

A customer is trying to restore a VPN connection configured on a FortiGate. Exhibits show output during a troubleshooting session when the VPN was working and the current baseline VPN configuration.

Question # 2

Which configuration parameters will restore VPN connectivity based on the diagnostic output?

Options:

A.

NSE8_812 Question 2 Option 1


B.

2


C.

2


D.

2


Expert Solution
Questions # 3:

Refer to the exhibit.

Question # 3

A customer is trying to setup a Playbook automation using a FortiAnalyzer, FortiWeb and FortiGate. The intention is to have the FortiGate quarantine any source of SQL Injection detected by the FortiWeb. They got the automation stitch to trigger on the FortiGate when simulating an attack to their website, but the quarantine object was created with the IP 0.0.0.0. Referring to the configuration and logs in the exhibits, which two statements are true? (Choose two.)

Options:

A.

The Group By option in the handler should be different to src, so src can be used on the Playbook configuration.


B.

FortiSOC Playbooks combining FortiWeb and FortiGate are not supported.


C.

To diagnose this issue, you need to use the commanddiagnose test application oftpd 22.


D.

The FortiAnalyzer ADOM Type must be Fabric.


E.

To fix the issue the parameter for script on the Playbook configuration should be epip.


Expert Solution
Questions # 4:

You want to use the MTA adapter feature on FortiSandbox in an HA-Cluster. Which statement about this solution is true?

Options:

A.

The configuration of the MTA Adapter Local Interface is different than on port1.


B.

The MTA adapter is only available in the primary node.


C.

The MTA adapter mode is only detection mode.


D.

The configuration is different than on a standalone device.


Expert Solution
Questions # 5:

Refer to the exhibit, which shows an SD-WAN configuration.

Question # 5

You configured the SD-WAN from Branch1 to the HUB and enabled packet duplication. You later notice that the traffic is not being duplicated. In this scenario, what is causing this problem?

Options:

A.

There is a mismatch in the FortiOS version between Branch1 and HUB.


B.

Traffic cannot be duplicated over multiple zones.


C.

Packet duplication is not enabled on the HUB side.


D.

Packet duplication did not occur because an interface is out of SLA.


Expert Solution
Questions # 6:

An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the Online Certificate Status Protocol (OCSP) server.

Part of the FortiGate configuration is shown below:

Question # 6

Based on this configuration, which two statements are true? (Choose two.)

Options:

A.

OCSP checks will always go to the configured FortiAuthenticator


B.

The OCSP check of the certificate can be combined with a certificate revocation list.


C.

OCSP certificate responses are never cached by the FortiGate.


D.

If the OCSP server is unreachable, authentication will succeed if the certificate matches the CA.


Expert Solution
Questions # 7:

A retail customer with a FortiADC HA cluster load balancing five webservers in L7 Full NAT mode is receiving reports of users not able to access their website during a sale event. But for clients that were able to connect, the website works fine.

CPU usage on the FortiADC and the web servers is low, application and database servers are still able to handle more traffic, and the bandwidth utilization is under 30%.

Which two options can resolve this situation? (Choose two.)

Options:

A.

Change the persistence rule to LB_PERSIS_SSL_SESSJD.


B.

Add more web servers to the real server poof


C.

Disable SSL between the FortiADC and the web servers


D.

Add a connection-pool to the FortiADC virtual server


Expert Solution
Questions # 8:

Refer to the exhibit of a FortiNAC configuration.

Question # 8

In this scenario, which two statements are correct? (Choose two.)

Options:

A.

A device that is modeled in FortiNAC is connected on VLAN 4093.


B.

An unknown host is connected to port3.


C.

The IP address of the FortiSwitch is 10.12.240.2.


D.

Port8 is connected to a FortiGate in FortiLink mode.


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

You have deployed a security fabric with three FortiGate devices as shown in the exhibit. FGT_2 has the following configuration:

Question # 9

FGT_1 and FGT_3 are configured with the default setting. Which statement is true for the synchronization of fabric-objects?

Options:

A.

Objects from the FortiGate FGT_2 will be synchronized to the upstream FortiGate.


B.

Objects from the root FortiGate will only be synchronized to FGT__2.


C.

Objects from the root FortiGate will not be synchronized to any downstream FortiGate.


D.

Objects from the root FortiGate will only be synchronized to FGT_3.


Expert Solution
Questions # 10:

Refer to the exhibit.

Question # 10

Given the exhibit, which two statements about FortiGate FGSP HA cluster behavior are correct? (Choose two.)

Options:

A.

You can run FortiGate Virtual Router Redundancy Protocol (VRRP) high availability in addition to FGSP simultaneously.


B.

Session synchronization occurs over Layer 3 by default, and if unavailable it will then try Layer 2.


C.

You can selectively synchronize only specific sessions between FGSP cluster members.


D.

Cluster members will upgrade one at a time and failover during firmware upgrades.


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions