Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the Fortinet Fortinet Network Security Expert NSE8_812 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit showing a FortiSOAR playbook.

Question # 11

You are investigating a suspicious e-mail alert on FortiSOAR, and after reviewing the executed playbook, you can see that it requires intervention.

What should be your next step?

Options:

A.

Go to the Incident Response tasks dashboard and run the pending actions


B.

Click on the notification icon on FortiSOAR GUI and run the pending input action


C.

Run the Mark Drive by Download playbook action


D.

Reply to the e-mail with the requested Playbook action


Expert Solution
Questions # 12:

A customer is operating a FortiWeb cluster in a high volume active-active HA group consisting of eight FortiWeb appliances. One of the secondary members is handling traffic for one specific VIP.

What will happen with the traffic if that secondary FortiWeb appliance fails?

Options:

A.

Traffic will be redirected to the next appliance in the same traffic group.


B.

Traffic will be redistributed by the primary appliance to the remaining secondary appliances.


C.

Traffic will be redistributed by the primary appliance to the remaining secondary appliances that are configured to handle traffic for that specific VIP.


D.

Traffic will be redirected to the secondary member with the least number of sessions.


Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

FortiManager is configured with the Jinja Script under CLI Templates shown in the exhibit.

Which two statements correctly describe the expected behavior when running this template? (Choose two.)

Options:

A.

The Jinja template will automatically map the interface with "WAN" role on the managed FortiGate.


B.

The template will work if you change the variable format to $(WAN).


C.

The template will work if you change the variable format to {{ WAN }}.


D.

The administrator must first manually map the interface for each device with a meta field.


E.

The template will fail because this configuration can only be applied with a CLI or TCL script.


Expert Solution
Questions # 14:

Refer to the exhibits.

Question # 14

Question # 14

A customer is looking for a solution to authenticate the clients connected to a hardware switch interface of a FortiGate 400E.

Referring to the exhibits, which two conditions allow authentication to the client devices before assigning an IP address? (Choose two.)

Options:

A.

FortiGate devices with NP6 and hardware switch interfaces cannot support 802.1X authentication.


B.

Devices connected directly to ports 3 and 4 can perform 802 1X authentication.


C.

Ports 3 and 4 can be part of different switch interfaces.


D.

Client devices must have 802 1X authentication enabled


Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

You are operating an internal network with multiple OSPF routers on the same LAN segment. FGT_3 needs to be added to the OSPF network and has the configuration shown in the exhibit. FGT_3 is not establishing any OSPF connection.

What needs to be changed to the configuration to make sure FGT_3 will establish OSPF neighbors without affecting the DR/BDR election?

A)

Question # 15

B)

Question # 15

C)

Question # 15

D)

Question # 15

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

A customer wants FortiClient EMS configured to deploy to 1500 endpoints. The deployment will be integrated with FortiOS and there is an Active Directory server.

Given the configuration shown in the exhibit, which two statements about the installation are correct? (Choose two.)

Options:

A.

If no client update time is specified on EMS, the user will be able to choose the time of installation if they wish to delay.


B.

A client can be eligible for multiple enabled configurations on the EMS server, and one will be chosen based on first priority


C.

You can only deploy initial installations to Windows clients.


D.

You must use Standard or Enterprise SQL Server rather than the included SQL Server Express


E.

The Windows clients only require "File and Printer Sharing0 allowed and the rest is handled by Active Directory group policy


Expert Solution
Questions # 17:

A remote IT Team is in the process of deploying a FortiGate in their lab. The closed environment has been configured to support zero-touch provisioning from the FortiManager, on the same network, via DHCP options. After waiting 15 minutes, they are reporting that the FortiGate received an IP address, but the zero-touch process failed.

The exhibit below shows what the IT Team provided while troubleshooting this issue:

Question # 17

Which statement explains why the FortiGate did not install its configuration from the FortiManager?

Options:

A.

The FortiGate was not configured with the correct pre-shared key to connect to the FortiManager


B.

The DHCP server was not configured with the FQDN of the FortiManager


C.

The DHCP server used the incorrect option type for the FortiManager IP address.


D.

The configuration was modified on the FortiGate prior to connecting to the FortiManager


Expert Solution
Questions # 18:

Which two methods are supported for importing user defined Lookup Table Data into the FortiSIEM? (Choose two.)

Options:

A.

Report


B.

FTP


C.

API


D.

SCP


Expert Solution
Questions # 19:

Refer to the exhibits.

Question # 19

You must integrate a FortiMail and FortiSandbox Enhanced Cloud solution for a customer who is concerned about the e-mails being delayed for too long.

According to the configuration shown in the exhibits, which would be an expected behavior?

Options:

A.

FortiMail will relay valid e-mails to the mail server as soon as it is done with other local inspections.


B.

If an attachment is sent to the FortiSandbox while the job queue is full, the e-mail might be delayed for up to 30 minutes, then e-mail will be relayed to the mail server.


C.

FortiMail will not wait for results but only for attachments that have been already submitted to the FortiSandbox in the last 60 minutes.


D.

FortiMail will ignore the timeout value if content disarm and reconstruction (CDR) is enabled.


Expert Solution
Questions # 20:

What is the benefit of using FortiGate NAC LAN Segments?

Options:

A.

It provides support for multiple DHCP servers within the same VLAN.


B.

It provides physical isolation without changing the IP address of hosts.


C.

It provides support for IGMP snooping between hosts within the same VLAN


D.

It allows for assignment of dynamic address objects matching NAC policy.


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions