No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
-1
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Refer to the exhibit.
You must modify the MED value that FortiGate_1 advertises to a BGP neighbor in autonomous system AS 30.
Which parameter must be configured on FortiGate_1 to implement this?
Adistribute-list-out
Broute-map-out
Cprefix-list-out
Droute-overlap
You need to scale IBGP sessions and optimize the routing table in an IBGP network.
Which parameter should be configured?
Aneighbor-group
Bneighbor-range
Crecursive-next-hop
Droute-reflector-client
Refer to the exhibits.
The exhibit shows the ADVPN network topology and a partial BGP configuration. Which two parameters must be configured under config neighbor-range for the spokes shown?
Choose two
Aset prefix 10.0.12.0 255.255.255.0
Bset route-reflector-client enable
Cset neighbor-group advpn
Dset prefix 172.16.1.0 255.255.255.0
You need to update a firewall policy to block multiple websites for the subnet 172.165.58.0/24.
What must you do to block these addresses efficiently?
ACreate an application sensor and apply the application control profile to the firewall policy.
BCreate a URL niter and apply the web filter profile to the firewall policy.
CCreate an IP address external connector and apply it to the destination field of the firewall policy.
DCreate an Internet Service Database (ISDB) group and apply it to the destination field of the firewall policy.
Refer to the exhibit.
A partial VPN configuration is shown.
Which statement about this VPN IPsec Phase 1 configuration is correct?
AFortiGate will not add a route to its routing information base (RIB) or forwarding information base (FIB) when the dynamic tunnel is negotiated.
BThis configuration must include certificates associated peer IDs to enhance security.
CA separate interface is created for each dial-up tunnel, which can be slower and more resource intensive, especially in large networks.
DThis configuration is the best for networks with regular traffic intervals, providing a balance between connectivity assurance and resource utilization.
Refer to the exhibit.
A revision-history window at the FortiManager device layer is displayed.
The IT team is attempting to identify the administrator responsible for the latest update to the FortiGate device database. What can the IT team conclude?
AThe user script_manager, an API user from the Fortinet Developer Network (FDN). is retrieving a configuration.
BThe retrieve process was automatically triggered by a Remote FortiGate Directly (via CLI) script.
CTo identify the user who created the event, in the FortiManager system logs, they must use the type=script filter in the user field.
DTo identify the user who created the event, they must view it on the Configuration and Installation widget on FortiGate at the FortiManager device layer.
Refer to the exhibit.
The packet-capture output for a ClientHello message is displayed.
You are updating a firewall policy that includes SSL certificate inspection. You are capturing packets from traffic traversing this firewall policy.
Which two statements about the packet capture are correct?
Choose two
AThe subject alternative name (SAN) is necessary to apply security profiles.
BThe client support only TLS versions 1.2 and 1.3.
CYou can effectively apply a web filtering profile to this traffic.
DYou can effectively apply an antivirus security profile to this traffic.
Refer to the exhibits.
A policy-package conflict status and details from the import-device wizard in the Core1 VDOM are displayed.
When importing a policy package, the following message is shown for the Web_restrictions web filter profile and the deep-inspection SSL-SSH profile:
> The following objects were found having conflicts. Please confirm your settings, then continue.
The Web_restrictions and deep-inspection profiles are used by other FortiGate devices within FortiManager.
Which step must you take to resolve the issue?
ACreate uniquely named objects on FortiGate and reimport them into the policy package.
BRetrieve the FortiGate configuration to automatically export correct objects and policies.
CUse non-default object values because FortiManager is unable to alter default values.
DSelect the FortiManager configuration that accepts changes on FortiManager and preserves existing configurations on FortiGate devices.
Refer to the exhibits.
The configuration of the Windows PC, PC1, which has a default MTU of 1500 bytes, the FortiGate interfaces with an MTU of 1000 bytes, and the results of PC1 pinging server 172.16.0.251 are shown.
Why is the PC1 user unable to ping server 172.16.0.254 and receiving the message: Packet needs to be fragmented but DF set?
AThe user must adjust the TCP maximum segment size (MSS) to 1000 for the ping to succeed
BThe ip.flags.mf option must be enabled on FortiGate. The user must adjust the ping MTU to 1000 to succeed.
CThe user must account for the size of the Ethernet header when configuring the MTU value.
DFortiGate honors the do not fragment bit and the packets are dropped. The user must adjust the ping MTU to 972 to succeed.
Refer to the exhibits.
The system-administrator settings on a root FortiGate and the Security Fabric settings on a downstream FortiGate are displayed.
When prompted to sign in to the downstream FortiGate using Security Fabric, a user enters the single sign-on (SSO) provider credentials. What happens next for the user?
AThe user is redirected to the root FortiGate.
BThe user accesses the downstream FortiGate with super_admin_readonly privileges.
CThe user accesses the root FortiGate with AdminSSO privileges.
DThe user receives an authentication failure message.
Refer to the exhibit.
The network diagram shows Site 2 being added with a network segment that overlaps the existing VPN IPsec connection between the hub and Site 1.
Which IPsec Phase 2 configuration must be made on the FortiGate hub to enable equal-cost multipath (ECMP) routing when multiple remote sites connect using overlapping subnets?
ASet multipath to enable
BSet net-device to ecmp
CSet route-overlap to allow
DSet route-overlap to either use-new or use-old
Which action can be taken on FortiGate to block traffic through intrusion prevention system (IPS) protocol decoders, with emphasis on network transmission patterns and application signatures?
AEnable inspect all ports in flow mode
BUse application control to limit non-URL-based software handling.
CEnable application detection-based SD-WAN rules.
DUse the DNS filter to block application signatures and protocol decoders.
Refer to the exhibits.
The system-administrator settings on a root FortiGate and the Security Fabric settings on a downstream FortiGate are displayed.
When signing in with Security Fabric to the downstream FortiGate, a user enters the single sign-on (SSO) provider credentials.
What is the outcome?
AThe downstream FortiGate creates an SSO administrator account for AdminSSO with the super_admin profile.
BThe user accesses the downstream FortiGate with super_admin_readonly profile.
CThe user is prompted to create an administrator account for AdminSSO.
DThe downstream FortiGate relies on the root FortiGate and does not create an administrator account.
You need to enable direct communication among multiple spokes in an organization’s network. Each spoke has more than one Internet connection. The spokes must connect directly, without traversing the hub, and the links must automatically switch to the best available connection.
How can automatic detection and optimal link utilization between spokes be achieved?
ASet up OSPF routing over dynamic VPN tunnels between spokes.
BUse ADVPN 2.0 to facilitate dynamic direct tunnels and automatic link optimization.
CImplement SD-WAN policies at the hub and the spokes.
DEstablish dynamic VPN tunnels between spokes with predefined backup routes.
Refer to the exhibits.
The routing tables for FortiGate_A and FortiGate_B, along with a network topology, are displayed.
Why does FortiGate_B have only one external route available for 100.75.5.1/32?
AThe subnet 10.0.11.0/24 is not located in the FortiGate_B area.
BFortiGate_A advertises only one external route to FortiGate_B.
CThe route to 100.75.5.1/32 shown on FortiGate_B has the lowest cost.
Drfc-1583-compatible is not set to enable on FortiGate_B.
Refer to the exhibit.
FortiGate_A and FortiGate_B are members of a FortiGate Session Life Support Protocol (FGSP) cluster in an enterprise network.
While testing the cluster with the ping command, you monitor packet loss and see the displayed session-list output on FortiGate_B.
What is causing this output on FortiGate_B?
Asession-pickup-connectionless is set to disable on FortiGate_B.
BThe session synchronization is encrypted.
CFortiGate_B is configured in passive mode.
Dstandalone-config-sync is set to disable on FortiGate_B.
When implementing IKEv2 in a VPN topology, which two statements are correct?
Choose two
AUnlike IKEv1, it supports mode config.
BIt includes stronger Diffie-Hellman (DH) groups, such as Elliptic Curve (ECP) groups.
CIt supports the extensible authentication protocol (EAP).
DIt exchanges a minimum of two messages to establish a secure tunnel.
You receive a FortiAnalyzer alert warning that a 1 ТВ disk became full in one day. During the investigation, you find thousands of unusual DNS log requests, such as JHCMQK.website.com, with no answers. You later discover that DNS exfiltration is taking place through both UDP and TLS.
How can you prevent this data-theft technique?
AUse a file filter profile to protect against DNS exfiltration.
BUse an intrusion prevention system (IPS) profile and DNS exfiltration-related signatures.
CEnable DNS filter to protect against DNS exfiltration.
DEnable data loss prevention (DLP) to prevent DNS exfiltration.
While inspecting an enterprise network, you identify a suspicious packet with MAC address 00:09:0f:09:18:81.
Which two statements about this suspicious packet are correct?
Choose two
AThe suspicious packet is related to a cluster with a group-id value lower than 255.
BThe suspicious packet corresponds to a port with a physical index equal to 2.
CThe suspicious packet is related to a cluster that has VDOMs enabled
DThe suspicious packet is related to a cluster configured with the FortiGate Session Life Protocol (FGSP).
Refer to the exhibit.
A network diagram shows a hub-and-spokes deployment. You must deploy several spokes, including BGP configuration for the spokes that connect to the hub.
Which two commands would you use to minimize the configuration required on the hub?
Community Discussion