System and Network SettingsLogging and MonitoringFirewall Policies and NATRoutingFirewall AuthenticationFortinet Single Sign-On (FSSO)Certificate OperationsAntivirusWeb FilteringIntrusion Prevention and Application ControlIPsec VPNSD-WAN Configuration and MonitoringHigh AvailabilityDiagnostics and TroubleshootingFortiGate in the CloudFortiSASE
Based on the routing table in the exhibit, which two statements are correct?
Choose two
AA packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is disabled.
BA packet with the source IP address 10.100.110.10 arriving on port3 is allowed if strict RPF is disabled.
CA packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is enabled.
DA packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is enabled.
An administrator believes that the Collector Agent is not sending login events to FortiGate.
What is the most effective troubleshooting action?
AVerify if DC agent is enabled on the FortiGate.
BRestart the domain controller to refresh authentication services.
CCheck if TCP port 8000 is open between the collector agent and FortiGate.
DVerify if FortiGate is set to use LDAP authentication instead of FSSO.
Refer to the exhibit showing an SD-WAN zone configuration in the FortiGate GUI.
Based on the exhibit, which statement is correct?
AThe Underlay zone contains no member.
Bport2 and port3 are not assigned to a zone.
CThe Underlay zone is the zone by default.
DThe virtual-wan-link and overlay zones can be deleted.
Refer to the exhibits.
An administrator has configured the Web Filter Profile to block access to every social networking site except Facebook. However, when users attempt to reach Facebook.com, they are redirected to a FortiGuard web-filtering block page.
Based on the exhibits, which configuration change must the administrator make to permit Facebook while blocking every other social networking site?
ASet the Social Networking action as warning in the FortiGuard Category Based Filter.
BChange the Feature set of Web Filter Profile as Proxy-based.
CSet the Action as Exempt for www.facebook.com in the Static URL Filter.
DChange the type as Simple in the Static URL Filter section.
QuestionQ6
Antivirus
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Routing
QuestionQ8
Intrusion Prevention and Application Control
QuestionQ9
IPsec VPN
QuestionQ10
Firewall Policies and NAT
QuestionQ11
Firewall Authentication
QuestionQ12
Firewall Policies and NAT
QuestionQ13
IPsec VPN
QuestionQ14
High Availability
QuestionQ15
FortiGate in the Cloud
QuestionQ16
FortiSASE
QuestionQ17
Logging and Monitoring
QuestionQ18
Web Filtering
QuestionQ19
Diagnostics and Troubleshooting
QuestionQ20
Fortinet Single Sign-On (FSSO)
QuestionQ21
Diagnostics and Troubleshooting
QuestionQ22
Antivirus
QuestionQ23
Fortinet Single Sign-On (FSSO)
QuestionQ24
Routing
QuestionQ25
Web Filtering
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
An administrator manages a FortiGate model that supports NTurbo.
How does NTurbo acceleration improve antivirus performance?
AFor flow-based inspection, NTurbo creates two inspection sessions on the FortiGate device.
BFor proxy-based inspection, NTurbo buffers the whole file and then sends it to the antivirus engine.
CFor flow-based inspection, NTurbo establishes a dedicated data path to redirect traffic between the IPS engine and FortiGate ingress and egress interfaces.
DFor proxy-based inspection, NTurbo offloads traffic to the content processor.
Which two statements regarding equal-cost multi-path (ECMP) configuration on FortiGate are true?
Choose two
AIf SD-WAN is disabled, you configure the load balancing algorithm in config system settings.
BIf SD-WAN is disabled, you can configure the parameter v4-ecmp-mode to volume-based.
CIf SD-WAN is enabled, you control the load balancing algorithm with the parameter load-balance-mode.
DIf SD-WAN is enabled, you can configure routes with unequal distance and priority values to be part of ECMP.
Refer to the exhibits.
You have configured the application sensor and its corresponding firewall policy as shown in the exhibits.
You cannot access any Google applications, although you can access www.fortinet.com. Which two actions should you take to resolve the issue?
Choose two
AChange the Inspection mode to Flow-based.
BSet the action for Google in the Application and Filter Overrides section to Allow.
CAdd “Google”.com to the URL category in the security profile.
DSet SSL inspection to deep-content inspection.
EMove up Google in the Application and Filter Overrides section to set its priority to 1.
An administrator needs to configure dead peer detection (DPD) on an IPsec VPN to identify dead tunnels. FortiGate must send DPD probes only when there is no inbound traffic.
Which FortiGate DPD mode satisfies this requirement?
AOn Demand
BEnabled
COn Idle
DDisabled
Refer to the exhibits.
The exhibits display a FortiGate device network diagram and the firewall-policy, VIP, and IP-pool settings on the FortiGate device.
The WAN (port2) interface is assigned IP address 100.65.0.101/24.
The LAN (port4) interface is assigned IP address 10.0.11.254/24.
The first firewall policy has NAT enabled and uses the IP pool. The second firewall policy uses a VIP as its destination address.
Which IP address is used to source NAT (SNAT) internet traffic originating from a workstation with IP address 10.0.11.50?
A100.65.0.200
B100.65.0.102
C100.65.0.101
D10.0.11.254
A FortiGate firewall policy has active authentication configured, but the user cannot authenticate while accessing a website.
Which protocol must FortiGate permit even though the user cannot authenticate?
ATACACS+
BDNS
CLDAP
DKerberos
Refer to the exhibits.
A FortiGate network diagram, together with the FortiGate firewall-policy and IP-pool configuration, is shown.
Two PCs, PC1 and PC2, are connected behind the FortiGate and can successfully access the internet. However, after the administrator adds a third PC to the network (PC3), that PC cannot connect to the internet.
Based on the information in the exhibits, which two configuration options can the administrator use to resolve PC3's connectivity issue?
Choose two
AIn the IP pool configuration, set type to overload.
BIn the IP pool configuration, set endip to 100.65.0.112.
CIn the firewall policy, set match-vip to enable using CLI.
DIn the system settings, set Multiple Interface Policies to enable.
An administrator configured a dialup IPsec VPN on a FortiGate with add-route enabled, but the static route does not appear in the routing table.
Which two statements about this scenario are correct?
Choose two
AThe administrator must ensure phase 2 is successfully established.
BThe administrator must enable a dynamic routing protocol on the dialup interface.
CThe administrator must define the remote network correctly in the phase 2 selectors.
DThe administrator must use a policy route instead of a static route for add-route to work properly.
What is the primary FortiGate election process when the HA override setting is enabled?
AConnected monitored ports > HA uptime > Priority > FortiGate serial number
BConnected monitored ports > Priority > System uptime > FortiGate serial number
CConnected monitored ports > Priority > HA uptime > FortiGate serial number
DConnected monitored ports > System uptime > Priority > FortiGate serial number
Refer to the exhibit.
A partial cloud topology is displayed.
You deployed a FortiGate Cloud-Native Firewall (CNF) in AWS to enforce FortiGate CNF policies for EC2 instance traffic.
Which path does EC2 traffic follow from the EC2 instance to the internet?
AEC2 instance -> internet gateway (IGW) -> gateway load balancer (GWLB) -> FortiGate CNF -> internet
You are onboarding an agentless secure web gateway (SWG) endpoint for secure internet access (SIA).
What happens to the user’s nonweb traffic?
AAll the nonweb traffic will bypass FortiSASE.
BFortiSASE will use SWG to redirect nonweb traffic to FortiExtender.
CFortiSASE will use Firewall-as-a-Service (FWaaS) to redirect nonweb traffic.
DThe endpoint will use split tunneling to redirect nonweb traffic to FortiSASE.
Which two features does collector agent advanced mode provide?
Choose two
AAdvanced mode supports nested or inherited groups.
BAdvanced mode uses the Windows convention-NetBios: Domain\Username.
CIn advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
DIn advanced mode, security profiles can be applied only to user groups, not individual users.
A web filter profile named restrict_media-profile has been created with a daily category usage quota.
While adding the profile to a firewall policy, restrict_media-profile does not appear in the available web-profile drop-down list.
What could be the reason?
AThe inspection mode in the firewall policy is not matching with web filter profile feature set.
BThe web filter profile is already referenced in another firewall policy.
CThe naming convention used in the web filter profile is restricting it in the firewall policy.
DThe firewall policy is in no-inspection mode instead of deep-inspection.
Refer to the exhibit that shows debug flow output.
Which two conclusions can be drawn from the debug flow output?
Choose two
AThe default gateway is configured on port2.
BThe debug flow is for UDP traffic.
CThe matching firewall policy denies the traffic.
DThe RPF check fails.
You have configured the FortiGate device for FSSO. A user successfully logs in to Windows, but is denied Internet access.
What should the administrator check first?
AThe FortiGate firewall policy settings for SSL decryption.
BThe FortiGate FSSO active users list for user’s IP address.
CThe windows event viewer for failed login attempts.
DWhether the user is assigned to the correct AD group.
Refer to the exhibits.
The exhibits display the system performance output and the default high-memory-usage threshold configuration on a FortiGate device.
Based on the system performance output, which two outcomes are possible?
Choose two
AFortiGate drops new sessions.
BAdministrators can access FortiGate only through the console port.
CAdministrators can change the configuration.
DFortiGate has entered conserve mode.
Which three statements describe a flow-based antivirus profile?
Choose three
AFlow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
BFortiGate buffers the whole file but transmits to the client at the same time.
CFlow-based inspection optimizes performance compared to proxy-based inspection.
DThe IPS engine handles the process as a standalone.
EIf a virus is detected, the last packet is delivered to the client.
Which two capabilities characterize FortiGate FSSO agentless polling mode?
Choose two
AFortiGate does not support workstation check.
BFortiGate directs the collector agent to use a remote LDAP server.
CFortiGate uses the AD server as the collector agent.
DFortiGate uses the SMB protocol to read the event viewer logs from the DCs.
Refer to the exhibit.
An administrator created a new firewall address for use as the destination of a static route.
Why can the administrator not select the new address in the Destination field of the new static route?
AIn the new firewall address, the FQDN address must first be resolved.
BIn the new static route, the administrator must select Named Address.
CIn the new firewall address, Routing configuration must be enabled.
DIn the new static route, the administrator must first set the interface to port2.
Refer to the exhibits.
A web filter profile configuration and a firewall policy configuration are displayed. You are attempting to access www.facebook.com, but are redirected to a FortiGuard web-filtering block page.
Based on the exhibits, what could be causing this issue?
AThe web rating override configuration is incorrect.
BThe firewall policy inspection mode is incorrect.
CFor www.facebook.com, the URL filter action is incorrect.
DThe web filter profile feature set is configured incorrectly.
Community Discussion