Pass the Fortinet Fortinet Network Security Expert NSE8_812 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which two methods are supported for importing user defined Lookup Table Data into the FortiSIEM? (Choose two.)

Options:

A.

Report


B.

FTP


C.

API


D.

SCP


Expert Solution
Questions # 22:

A customer with a FortiDDoS 200F protecting their fibre optic internet connection from incoming traffic sees that all the traffic was dropped by the device even though they were not under a DoS attack. The traffic flow was restored after it was rebooted using the GUI. Which two options will prevent this situation in the future? (Choose two)

Options:

A.

Change the Adaptive Mode.


B.

Create an HA setup with a second FortiDDoS 200F


C.

Move the internet connection from the SFP interfaces to the LC interfaces


D.

Replace with a FortiDDoS 1500F


Expert Solution
Questions # 23:

Refer to the exhibits.

Question # 23

The exhibits show a diagram of a requested topology and the base IPsec configuration.

A customer asks you to configure ADVPN via two internet underlays. The requirement is that you use one interface with a single IP address on DC FortiGate.

In this scenario, which feature should be implemented to achieve this requirement?

Options:

A.

Use network-overlay id


B.

Change advpn2 to IKEv1


C.

Use local-id


D.

Use peer-id


Expert Solution
Questions # 24:

Refer to the exhibit.

Question # 24

What is happening in this scenario?

Options:

A.

The user status changed at FortiClient EMS to off-net.


B.

The user is authenticating against a FortiGate Captive Portal.

C The user is authenticating against an IdP.


C.

The user has not authenticated on their external browser.


Expert Solution
Questions # 25:

What is the benefit of using FortiGate NAC LAN Segments?

Options:

A.

It provides support for multiple DHCP servers within the same VLAN.


B.

It provides physical isolation without changing the IP address of hosts.


C.

It provides support for IGMP snooping between hosts within the same VLAN


D.

It allows for assignment of dynamic address objects matching NAC policy.


Expert Solution
Questions # 26:

Refer to the exhibit.

Question # 26

FortiManager is configured with the Jinja Script under CLI Templates shown in the exhibit.

Which two statements correctly describe the expected behavior when running this template? (Choose two.)

Options:

A.

The Jinja template will automatically map the interface with "WAN" role on the managed FortiGate.


B.

The template will work if you change the variable format to $(WAN).


C.

The template will work if you change the variable format to {{ WAN }}.


D.

The administrator must first manually map the interface for each device with a meta field.


E.

The template will fail because this configuration can only be applied with a CLI or TCL script.


Expert Solution
Questions # 27:

Refer to the exhibits.

Question # 27

Question # 27

The exhibits show a FortiGate network topology and the output of the status of high availability on the FortiGate.

Given this information, which statement is correct?

Options:

A.

The ethertype values of the HA packets are 0x8890, 0x8891, and 0x8892


B.

The cluster mode can support a maximum of four (4) FortiGate VMs


C.

The cluster members are on the same network and the IP addresses were statically assigned.


D.

FGVMEVLQOG33WM3D and FGVMEVGCJNHFYI4A share a virtual MAC address.


Expert Solution
Questions # 28:

An HA topology is using the following configuration:

Question # 28

Based on this configuration, how long will it take for a failover to be detected by the secondary cluster member?

Options:

A.

600ms


B.

200ms


C.

300ms


D.

100ms


Expert Solution
Questions # 29:

Refer to the CLI configuration of an SSL inspection profile from a FortiGate device configured to protect a web server:

Question # 29

Based on the information shown, what is the expected behavior when an HTTP/2 request comes in?

Options:

A.

FortiGate will reject all HTTP/2 ALPN headers.


B.

FortiGate will strip the ALPN header and forward the traffic.


C.

FortiGate will rewrite the ALPN header to request HTTP/1.


D.

FortiGate will forward the traffic without modifying the ALPN header.


Expert Solution
Questions # 30:

Refer to the exhibit, which shows the high availability configuration for the FortiAuthenticator (FAC1).

Question # 30

Based on this information, which statement is true about the next FortiAuthenticator (FAC2) member that will join an HA cluster with this FortiAuthenticator (FAC1)?

Options:

A.

FAC2 can only process requests when FAC1 fails.


B.

FAC2 can have its HA interface on a different network than FAC1.


C.

The FortiToken license will need to be installed on the FAC2.


D.

FSSO sessions from FAC1 will be synchronized to FAC2.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions