You configured an outgoing firewall policy with a Web filter profile for accessing the Internet. The access to URL https://www.it-acme.com and all Web sites belonging to the same category should be blocked. You notice that the Web server presents a certificate with CN=www.acme.com site is categorized as "Information Technology" and the www.acme.com site is categorized as "Business".
Which statement is correct in this scenario?
Answer : C
Click the Exhibit button. A customer has just finished their Azure deployment to secure a Web application behind a FortiGate and a FortiWeb. Now they want to add components to protect against advanced threats (zero day attacks), centrally manage the entire environment, and centrally monitor Fortinet and non-Fortinet products.
Which Fortinet solutions will satisfy these requirements?
Answer : C
Click the Exhibit button.
Referring to the exhibit, what will happen if FortiSandbox categorizes an e-mail attachment submitted by FortiMail as a high risk?
Answer : B
Click the Exhibit button. Referring to the exhibit, which two statements are true? (Choose two.)
Answer : AD
Click the Exhibit button.
You configured AV and Web filtering for your outgoing Internet connections. You later noticed that not all Web sessions are being inspected and you start troubleshooting the problem.
Referring to the exhibit, what would cause this problem?
Answer : C
Click the Exhibit button.
You have two data centers a FortiGate 7000-series chassis connected by VPN, and all traffic flows over an established generic routing encapsulation (GRE) tunnel between them. You are troubleshooting traffic that is traversing between Server VLAN A and Server VLAN B. The performance is lower than expected and all traffic is only on the FPM module in slot 3.
Answer : C
Answer : BD
You are asked to add a FortiDDoS to the network to combat detected slow connection attacks such as Slowloris.
Which prevention mode on FortiDDoS will protect you against this specific type of attack?
Answer : A
root and vd-lan. The root VDOM provides external SSL-VPN
Answer : BD
Click the Exhibit button. When deploying a new FortiGate-VMX Security node, an administrator received the error message shown in the exhibit.
In this scenario, which statement is correct?
Answer : D
Click the Exhibit button.
Your organization has a FortiGate cluster that is connected to two independent ISPs. You must configure the FortiGate failover for a single ISP failure to occur without disruption. Referring to the exhibit, which two FortiGate BGP features would be used to accomplish this task? (Choose two.)
Answer : AC
An old router has been replaced by a FortiWAN device. The FortiWAN has inherited the router"™s management IP address and now the network administrator needs to remove the old router from the FortiSIEM configuration.
Which two statements are true about this operation? (Choose two.)
Answer : AB
You have a customer experiencing problems with a legacy L3/L4 firewall device and the IPv6 SIP VoIP traffic. Their device is dropping SIP packets, consequently, it cannot process SIP voice calls. Which solution would solve the customer"™s problem?
Answer : D
Click the Exhibit button. An administrator implements a multi-chassis link aggregation (MCLAG) solution using two FortiSwitch 448Ds and one FortiGate 3700D.
As describes in the network topology shown in the exhibit, two links are connected to each FortiSwitch. What is requires to implement this solution? (Choose two.)
Answer : CD
Click the Exhibit button.
The exhibit shows a full-mesh topology between FortiGates and FortiSwitches. To deploy this configuration, two requirements must be met:
-20 Gbps full duplex connectivity is available between each FortiGate and the FortiSwitches
-The FortiGate HA must be in AP mode.
Answer : AC
Have any questions or issues ? Please dont hesitate to contact us