版權說明:本文檔由用戶提供并上傳,收益歸屬內容提供方,若內容存在侵權,請進行舉報或認領
文檔簡介
PAGEPAGE1NSE-4(英文版)認證考試題庫(含答案)一、單選題1.TheHTTPinspectionprocessinwebfilteringfollowsaspecificorderwhenmultiplefeaturesareenabledin
Thewebfilterprofile.WhatordermustFortiGateusewhenthewebfilterprofilehasfeaturesenabled,suchas
Safesearch?A、DNS-basedwebfilterandproxy-basedwebfilterB、StaticURLfilter,FortiGuardcategoryfilter,andadvancedfiltersC、Staticdomainfilter,SSLinspectionfilter,andexternalconnectorsfiltersD、FortiGuardcategoryfilterandratingfilter答案:B2.WhichstatementaboutvideofilteringonFortiGateistrue?A、FullSSLInspectionisnotrequired.B、Itisavailableonlyonaproxy-basedfirewallpolicy.C、Itinspectsvideofileshostedonfilesharingservices.D、VideofilteringFortiGuardcategoriesarebasedonwebfilterFortiGuardcategories.答案:B3.Examinethefollowingwebfilteringlog.Whichstatementaboutthelogmessageistrue?A、TheactionforthecategoryGamesissettoblock.B、TheusagequotafortheIPaddress0.hasexpiredC、Thenameoftheappliedwebfilterprofileisdefault.D、Thewebsiteminiclip.matchesastaticURLfilterwhoseactionissettoWarning.答案:C4.AnadministratorhasconfiguredastrictRPFcheckonFortiGate.WhichstatementistrueaboutthestrictRPF
Check?A、ThestrictRPFcheckisrunonthefirstsentandreplypacketofanynewsession.B、StrictRPFchecksthebestroutebacktothesourceusingtheininginterface.C、StrictRPFchecksonlyfortheexistenceofatleastoneactiveroutebacktothesourceusingthe
Ininginterface.D、StrictRPFallowspacketsbacktosourceswithallactiveroutes.答案:B5.WhichCLImandwilldisplaysessionsbothfromclienttotheproxyandfromtheproxytotheservers?A、diagnosewadsessionlistB、diagnosewadsessionlist|grephook-pre&&hook-outC、diagnosewadsessionlist|grephook=pre&&hook=outD、diagnosewadsessionlist|grep"hook=pre"&"hook=out"答案:A6.WhatistheprimaryFortiGateelectionprocesswhentheHAoverridesettingisdisabled?A、Connectedmonitoredports>Systemuptime>Priority>FortiGateSerialnumberB、Connectedmonitoredports>HAuptime>Priority>FortiGateSerialnumberC、Connectedmonitoredports>Priority>HAuptime>FortiGateSerialnumberD、Connectedmonitoredports>Priority>Systemuptime>FortiGateSerialnumber答案:B7.Refertothewebfilterrawlogs.
Basedontherawlogsshownintheexhibit,whichstatementiscorrect?A、Socialnetworkingwebfiltercategoryisconfiguredwiththeactionsettoauthenticate.B、TheactiononfirewallpolicyID1issettowarning.C、Accesstothesocialnetworkingwebfiltercategorywasexplicitlyblockedtoallusers.D、Thenameofthefirewallpolicyisall_users_web.答案:A8.AnadministratorhasconfiguredoutgoingInterfaceanyinafirewallpolicy.Whichstatementistrueaboutthe
Policylistview?A、Policylookupwillbedisabled.B、BySequenceviewwillbedisabled.C、SearchoptionwillbedisabledD、InterfacePairviewwillbedisabled.答案:D9.WhichcertificatevaluecanFortiGateusetodeterminetherelationshipbetweentheissuerandthecertificate?A、SubjectKeyIdentifiervalueB、SMMIECapabilitiesvalueC、SubjectvalueD、SubjectAlternativeNamevalue答案:A10.ExaminetheIPSsensorconfigurationshownintheexhibit,andthen答案thequestionbelow.AnadministratorhasconfiguredtheWINDOWS_SERVERSIPSsensorinanattempttodeterminewhethertheinfluxofHTTPStrafficisanattackattemptornot.AfterapplyingtheIPSsensor,FortiGateisstillnotgeneratinganyIPSlogsfortheHTTPStraffic.Whatisapossiblereasonforthis?A、TheIPSfilterismissingtheProtocol:HTTPSoption.B、TheHTTPSsignatureshavenotbeenaddedtothesensor.C、ADoSpolicyshouldbeused,insteadofanIPSsensor.D、ADoSpolicyshouldbeused,insteadofanIPSsensor.E、ThefirewallpolicyisnotusingafullSSLinspectionprofile.答案:E11.IftheIssuerandSubjectvaluesarethesameinadigitalcertificate,whichtypeofentitywasthecertificateissuedto?A、ACRLB、ApersonC、AsubordinateCAD、ArootCA答案:D12.WhichcertificatevaluecanFortiGateusetodeterminetherelationshipbetweentheissuerandthecertificate?A、SubjectKeyIdentifiervalueB、SMMIECapabilitiesvalueC、SubjectvalueD、SubjectAlternativeNamevalue答案:A13.AFortiGateisoperatinginNATmodeandconfiguredwithtwovirtualLAN(VLAN)subinterfacesaddedtothephysicalinterface.WhichstatementsabouttheVLANsubinterfacescanhavethesameVLANID,onlyiftheyhaveIPaddressesindifferentsubnets.A、ThetwoVLANsubinterfacescanhavethesameVLANID,onlyiftheyhaveIPaddressesindifferentsubnets.B、ThetwoVLANsubinterfacesmusthavedifferentVLANIDs.C、ThetwoVLANsubinterfacescanhavethesameVLANID,onlyiftheybelongtodifferentVDOMs.D、ThetwoVLANsubinterfacescanhavethesameVLANID,onlyiftheyhaveIPaddressesinthesamesubnet.答案:B14.WhichofstatementistrueaboutSSLVPNwebmode?A、Thetunnelisupwhiletheclientisconnected.B、Itsupportsalimitednumberofprotocols.C、TheexternalnetworkapplicationsendsdatathroughtheVPN.D、ItassignsavirtualIPaddresstotheclient.答案:B15.WhichscanningtechniqueonFortiGatecanbeenabledonlyontheCLI?A、HeuristicsscanB、TrojanscanC、AntivirusscanD、Ransomwarescan答案:A16.Refertotheexhibit.
Theexhibitcontainsanetworkdiagram,virtualIP,IPpool,andfirewallpoliciesconfiguration.
TheWAN(port1)interfacehastheIPaddress/24.
TheLAN(port3)interfacehastheIPaddress10..0.1.254./24.
ThefirstfirewallpolicyhasNATenabledusingIPPool.
ThesecondfirewallpolicyisconfiguredwithaVIPasthedestinationaddress.
WhichIPaddresswillbeusedtosourceNATtheinternettrafficingfromaworkstationwiththeIPaddress0?A、.B、.C、00.D、0.答案:A17.AnadministratorwantstoconfigureDeadPeerDetection(DPD)onIPSECVPNfordetectingdeadtunnels.
TherequirementisthatFortiGatesendsDPDprobesonlywhennotrafficisobservedinthetunnel.
WhichDPDmodeonFortiGatewillmeettheaboverequirement?A、DisabledB、OnDemandC、EnabledD、OnIdle答案:D18.WhichstatementaboutvideofilteringonFortiGateistrue?A、VideofilteringFortiGuardcategoriesarebasedonwebfilterFortiGuardcategories.B、ItdoesnotrequireaseparateFortiGuardlicense.C、FullSSLinspectionisnotrequired.D、Otisavailableonlyonaproxy-basedfirewallpolicy.答案:B19.Refertotheexhibit.
Examinetheintrusionpreventionsystem(IPS)diagnosticmand.
WhichstatementiscorrectIfoption5wasusedwiththeIPSdiagnosticmandandtheoutewasa
DecreaseintheCPUusage?A、TheIPSenginewasinspectinghighvolumeoftraffic.B、TheIPSenginewasunabletopreventanintrusionattack.C、TheIPSenginewasblockingalltraffic.D、TheIPSenginewillcontinuetoruninanormalstate.答案:A20.WhichCLImandwilldisplaysessionsbothfromclienttotheproxyandfromtheproxytotheservers?A、diagnosewadsessionlistB、diagnosewadsessionlist|grephook-pre&&hook-outC、diagnosewadsessionlist|grephook=pre&&hook=outD、diagnosewadsessionlist|grep"hook=pre"&"hook=out"答案:A21.ExaminethisFortiGateconfiguration:Examinetheoutputofthefollowingdebugmand:Basedonthediagnosticoutputsabove,howistheFortiGatehandlingthetrafficfornewsessionsthatrequireinspection?A、Itisallowed,butwithnoinspectionB、ItisallowedandinspectedaslongastheinspectionisflowbasedC、Itisdropped.D、Itisallowedandinspected,aslongastheonlyinspectionrequiredisantivirus.答案:C22.Refertothewebfilterrawlogs.Basedontherawlogsshownintheexhibit,whichstatementiscorrect?A、Socialnetworkingwebfiltercategoryisconfiguredwiththeactionsettoauthenticate.B、TheactiononfirewallpolicyID1.issettowarning.C、Accesstothesocialnetworkingwebfiltercategorywasexplicitlyblockedtoallusers.D、Thenameofthefirewallpolicyisall_users_web.答案:A23.Refertotheexhibit.
Whichcontainsanetworkdiagramandroutingtableoutput.
TheStudentisunabletoaccessWebserver.
Whatisthecauseoftheproblemandwhatisthesolutionfortheproblem?A、ThefirstpacketsentfromStudentfailedtheRPFcheck.
Thisissuecanberesolvedbyaddingastaticrouteto/24throughwan1.B、ThefirstreplypacketforStudentfailedtheRPFcheck.
Thisissuecanberesolvedbyaddingastaticrouteto/24throughwan1.C、ThefirstreplypacketforStudentfailedtheRPFcheck.
Thisissuecanberesolvedbyaddingastaticrouteto4/32throughport3.D、ThefirstpacketsentfromStudentfailedtheRPFcheck.答案:D24.WhichfeatureintheSecurityFabrictakesoneormoreactionsbasedoneventtriggers?A、FabricConnectorsB、AutomationStitchesC、SecurityRatingD、LogicalTopology答案:B25.Refertotheexhibitstoviewthefirewallpolicy(ExhibitA)andtheantivirusprofile(ExhibitB).
Whichstatementiscorrectifauserisunabletoreceiveablockreplacementmessagewhendownloadingan
Infectedfileforthefirsttime?A、Thefirewallpolicyperformsthefullcontentinspectiononthefile.B、Theflow-basedinspectionisused,whichresetsthelastpackettotheuser.C、ThevolumeoftrafficbeinginspectedistoohighforthismodelofFortiGate.D、Theintrusionpreventionsecurityprofileneedstobeenabledwhenusingflow-basedinspectionmode.答案:B26.AnetworkadministratorisconfiguringanewIPsecVPNtunnelonFortiGate.TheremotepeerIPaddressisdynamic.Inaddition,theremotepeerdoesnotsupportadynamicDNSupdateservice.WhattypeofremotegatewayshouldtheadministratorconfigureonFortiGateforthenewIPsecVPNtunneltowork?A、StaticIPAddressB、DialupUserC、DynamicDNSD、Pre-sharedKey答案:B27.Refertotheexhibit,whichcontainsasessiondiagnosticoutput.
Whichstatementistrueaboutthesessiondiagnosticoutput?A、ThesessionisaUDPunidirectionalstate.B、ThesessionisinTCPESTABLISHEDstate.C、ThesessionisabidirectionalUDPconnection.D、ThesessionisabidirectionalTCPconnection.答案:C28.Refertotheexhibit.Examinetheintrusionpreventionsystem(IPS)diagnosticmand.
WhichstatementiscorrectIfoption5.wasusedwiththeIPSdiagnosticmandandtheoutewasadecreaseintheCPUusage?A、TheIPSenginewasinspectinghighvolumeoftraffic.B、TheIPSenginewasunabletopreventanintrusionattack.C、TheIPSenginewasblockingalltraffic.D、TheIPSenginewillcontinuetoruninanormalstate.答案:A29.WhydoesFortiGateKeepTCPsessionsinthesessiontableforseveralseconds,evenafterbothsides(client
Andserver)haveterminatedthesession?A、Toallowforout-of-orderpacketsthatcouldarriveaftertheFIN/ACKpacketsB、TofinishanyinspectionoperationsC、ToremovetheNAToperationD、Togeneratelogs答案:A30.AnetworkadministratorhasenabledfullSSLinspectionandwebfilteringonFortiGate.Whenvisitingany
HTTPSwebsites,thebrowserreportscertificatewarningerrors.WhenvisitingHTTPwebsites,thebrowser
Doesnotreporterrors.
Whatisthereasonforthecertificatewarningerrors?A、Thebrowserrequiresasoftwareupdate.B、FortiGatedoesnotsupportfullSSLinspectionwhenwebfilteringisenabled.C、TheCAcertificatesetontheSSL/SSHinspectionprofilehasnotbeenimportedintothebrowser.D、Therearenetworkconnectivityissues.答案:C31.Refertotheexhibit.
TheglobalsettingsonaFortiGatedevicemustbechangedtoalignwithpanysecuritypolicies.Whatdoes
TheAdministratoraccountneedtoaccesstheFortiGateglobalsettings?A、ChangepasswordB、EnablerestrictaccesstotrustedhostsC、ChangeAdministratorprofileD、Enabletwo-factorauthentication答案:C32.Which
Statementiscorrectregardingtheinspectionofsomeoftheservicesavailablebywebapplicationsembedded
Inthird-partywebsites?A、Thesecurityactionsappliedonthewebapplicationswillalsobeexplicitlyappliedonthethird-partywebsites.B、Theapplicationsignaturedatabaseinspectstrafficonlyfromtheoriginalwebapplicationserver.C、FortiGuardmaintainsonlyonesignatureofeachwebapplicationthatisunique.D、FortiGatecaninspectsub-applicationtrafficregardlesswhereitwasoriginated.答案:D33.OnFortiGate,whichtypeoflogsrecordinformationabouttrafficdirectlytoandfromtheFortiGate
ManagementIPaddresses?A、SystemeventlogsB、ForwardtrafficlogsC、LocaltrafficlogsD、Securitylogs答案:C34.Refertotheexhibit.
AnadministratoraddedaconfigurationforanewRADIUSserver.Whileconfiguring,theadministrator
SelectedtheIncludeineveryusergroupoption.
WhatistheimpactofusingtheIncludeineveryusergroupoptioninaRADIUSconfiguration?A、ThisoptionplacestheRADIUSserver,andalluserswhocanauthenticateagainstthatserver,intoevery
FortiGateusergroup.B、ThisoptionplacesallFortiGateusersandgroupsrequiredtoauthenticateintotheRADIUSserver,
Which,inthiscase,isFortiAuthenticator.C、ThisoptionplacesallusersintoeveryRADIUSusergroup,includinggroupsthatareusedfortheLDAP
ServeronFortiGate.D、ThisoptionplacestheRADIUSserver,andalluserswhocanauthenticateagainstthatserver,intoevery
RADIUSgroup.答案:A35.Refertotheexhibits.
TheSSLVPNconnectionfailswhenauserattemptstoconnecttoit.Whatshouldtheuserdotosuccessfully
ConnecttoSSLVPN?A、ChangetheSSLVPNportontheclient.B、ChangetheServerIPaddress.C、Changetheidle-timeout.D、ChangetheSSLVPNportaltothetunnel.答案:A36.Refertotheexhibittoviewtheapplicationcontrolprofile.UserswhouseAppleFaceTimevideoconferencesareunabletosetupmeetings.Inthisscenario,whichstatementistrue?A、AppleFaceTimebelongstothecustommonitoredfilter.B、ThecategoryofAppleFaceTimeisbeingmonitored.C、AppleFaceTimebelongstothecustomblockedfilter.D、ThecategoryofAppleFaceTimeisbeingblocked.答案:C37.Refertotheexhibittoviewthefirewallpolicy.Whichstatementiscorrectifwell-knownvirusesarenotbeingblocked?A、Thefirewallpolicydoesnotapplydeepcontentinspection.B、Thefirewallpolicymustbeconfiguredinproxy-basedinspectionmode.C、Theactiononthefirewallpolicymustbesettodeny.D、Webfiltershouldbeenabledonthefirewallpolicytoplementtheantivirusprofile.答案:A38.WhichSecurityratingscorecardhelpsidentifyconfigurationweaknessandbestpracticeviolationsinyournetwork?A、FabricCoverageB、AutomatedResponseC、SecurityPostureD、Optimization答案:C39.WhichfeatureintheSecurityFabrictakesoneormoreactionsbasedoneventtriggers?A、FabricConnectorsB、AutomationStitchesC、SecurityRatingD、LogicalTopology答案:B40.AnetworkadministratorhasenabledfullSSLinspectionandwebfilteringonFortiGate.WhenvisitinganyHTTPSwebsites,thebrowserreportscertificatewarningerrors.WhenvisitingHTTPwebsites,thebrowserdoesnotreporterrors.Whatisthereasonforthecertificatewarningerrors?A、Thebrowserrequiresasoftwareupdate.B、FortiGatedoesnotsupportfullSSLinspectionwhenwebfilteringisenabled.C、TheCAcertificatesetontheSSL/SSHinspectionprofilehasnotbeenimportedintothebrowser.D、Therearenetworkconnectivityissues.答案:C41.Ateammanagerhasdecidedthat,whilesomemembersoftheteamneedaccesstoaparticularwebsite,the
MajorityoftheteamdoesnotWhichconfigurationoptionisthemosteffectivewaytosupportthisrequest?A、ImplementawebfiltercategoryoverrideforthespecifiedwebsiteB、ImplementaDNSfilterforthespecifiedwebsite.C、ImplementwebfilterquotasforthespecifiedwebsiteD、Implementwebfilterauthenticationforthespecifiedwebsite.答案:D42.WhichtimeoutsettingcanberesponsiblefordeletingSSLVPNassociatedsessions?A、SSLVPNidle-timeoutB、SSLVPNhttp-request-body-timeoutC、SSLVPNlogin-timeoutD、SSLVPNdtls-hello-timeout答案:A43.Refertotheexhibits.ExhibitAExhibitBAnadministratorcreatesanewaddressobjectontherootFortiGate(Local-FortiGate)inthesecurityfabric.Aftersynchronization,thisobjectisnotavailableonthedownstreamFortiGate(ISFW).Whatmusttheadministratordotosynchronizetheaddressobject?A、ChangethecsfsettingonLocal-FortiGate(root)tosecconfiguration-synclocal.B、ChangethecsfsettingonISFW(downstream)tosecconfiguracion-synclocal.C、ChangethecsfsettingonLocal-FortiGate(root)tosecfabric-objecc-unificaciondefaulc.D、ChangethecsfsettingonISFW(downstream)tosecfabric-objecc-unificaciondefaulc.答案:A44.WhatisthelimitationofusingaURLlistandapplicationcontrolonthesamefirewallpolicy,inNGFW
Policy-basedmode?A、ItlimitsthescanningofapplicationtraffictotheDNSprotocolonly.B、Itlimitsthescanningofapplicationtraffictouseparentsignaturesonly.C、Itlimitsthescanningofapplicationtraffictothebrowser-basedtechnologycategoryonly.D、Itlimitsthescanningofapplicationtraffictotheapplicationcategoryonly.答案:D45.hichstatementaboutthepolicyIDnumberofafirewallpolicyistrue?A、ItisrequiredtomodifyafirewallpolicyusingtheCLI.B、Itrepresentsthenumberofobjectsusedinthefirewallpolicy.C、Itchangeswhenfirewallpoliciesarereordered.D、Itdefinestheorderinwhichrulesareprocessed.答案:A46.Examinethetwostaticroutesshownintheexhibit,then答案thefollowingquestion.WhichofthefollowingistheexpectedFortiGatebehaviorregardingthesetworoutestothesamedestination?A、FortiGatewillloadbalancealltrafficacrossbothroutes.B、FortiGatewillusetheport1.routeastheprimarycandidate.C、FortiGatewillroutetwiceasmuchtraffictotheport2.routeD、FortiGatewillonlyactuatetheport1.routeintheroutingtable答案:B47.Refertotheexhibit,whichcontainsastaticrouteconfiguration.AnadministratorcreatedastaticrouteforAmazonWebServices.WhatCLImandmusttheadministratorusetoviewtheroute?A、getrouterinforouting-tableallB、getinternetserviceroutelistC、getrouterinforouting-tabledatabaseD、diagnosefirewallproutelist答案:D48.WhichstatementcorrectlydescribesNetAPIpollingmodefortheFSSOcollectoragent?A、ThecollectoragentusesaWindowsAPItoqueryDCsforuserlogins.B、NetAPIpollingcanincreasebandwidthusageinlargenetworks.C、Thecollectoragentmustsearchsecurityeventlogs.D、TheNetSessionEnumfunctionisusedtotrackuserlogouts.答案:D49.WhatinspectionmodedoesFortiGateuseifitisconfiguredasapolicy-basednext-generationfirewall
(NGFW)?A、FullContentinspectionB、Proxy-basedinspectionC、CertificateinspectionD、Flow-basedinspection答案:D50.AnadministratordoesnotwanttoreportthelogoneventsofserviceaccountstoFortiGate.Whatsettingonthecollectoragentisrequiredtoachievethis?A、AddthesupportofNTLMauthentication.B、AdduseraccountstoActiveDirectory(AD).C、AdduseraccountstotheFortiGategroupfitter.D、AdduseraccountstotheIgnoreUserList.答案:D51.Whichstatementregardingthefirewallpolicyauthenticationtimeoutistrue?A、Itisanidletimeout.TheFortiGateconsidersausertobe"idle"ifitdoesnotseeanypacketsingfromtheuser'ssourceIP.B、Itisahardtimeout.TheFortiGateremovesthetemporarypolicyforauser'ssourceIPaddressafterthistimerhasexpired.C、Itisanidletimeout.TheFortiGateconsidersausertobe"idle"ifitdoesnotseeanypacketsingfromtheuser'ssourceMAC.D、Itisahardtimeout.TheFortiGateremovesthetemporarypolicyforauser'ssourceMACaddressafterthistimerhasexpired.答案:A52.Examinethisoutputfromadebugflow:
WhydidtheFortiGatedropthepacket?A、Thenext-hopIPaddressisunreachable.B、ItfailedtheRPFcheck.C、ItmatchedanexplicitlyconfiguredfirewallpolicywiththeactionDENY.D、Itmatchedthedefaultimplicitfirewallpolicy.答案:D53.AnadministratormustdisableRPFchecktoinvestigateanissue.WhichmethodisbestsuitedtodisableRPFwithoutaffectingfeatureslikeantivirusandintrusionpreventionsystem?A、Enableasymmetricrouting,sotheRPFcheckwillbebypassed.B、DisabletheRPFcheckattheFortiGateinterfacelevelforthesourcecheck.C、DisabletheRPFcheckattheFortiGateinterfacelevelforthereplycheck.D、Enableasymmetricroutingattheinterfacelevel.答案:B54.WhichtypeoflogsonFortiGaterecordinformationabouttrafficdirectlytoandfromthe
FortiGatemanagementIPaddresses?A、SystemeventlogsB、ForwardtrafficlogsC、LocaltrafficlogsD、Securitylogs答案:C55.Refertotheexhibit.TheexhibitcontainstheconfigurationforanSD-WANPerformanceSLA,aswellastheoutputofdiagnosesysvirtual-wan-linkhealth-check.Whichinterfacewillbeselectedasanoutgoinginterface?A、port2.B、port4.C、port3.D、port1.答案:D56.Refertotheexhibits.TheSSLVPNconnectionfailswhenauserattemptstoconnecttoit.WhatshouldtheuserdotosuccessfullyconnecttoSSLVPN?A、ChangetheSSLVPNportontheclient.B、ChangetheServerIPaddress.C、Changetheidle-timeout.D、ChangetheSSLVPNportaltothetunnel.答案:A57.WhichscanningtechniqueonFortiGatecanbeenabledonlyontheCLI?A、HeuristicsscanB、TrojanscanC、AntivirusscanD、Ransomwarescan答案:A58.Whenconfiguringafirewallvirtualwirepairpolicy,whichfollowingstatementistrue?A、Onlyasinglevirtualwirepaircanbeincludedineachpolicy.B、Anynumberofvirtualwirepairscanbeincludedineachpolicy,regardlessofthepolicytrafficdirectionsettings.C、Anynumberofvirtualwirepairscanbeincluded,aslongasthepolicytrafficdirectionisthesame.D、Exactlytwovirtualwirepairsneedtobeincludedineachpolicy.答案:A59.WhichstatementaboutthepolicyIDnumberofafirewallpolicyistrue?A、Itchangeswhenfirewallpoliciesarereordered.B、Itrepresentsthenumberofobjectsusedinthefirewallpolicy.C、ItisrequiredtomodifyafirewallpolicyusingtheCLI.D、Itdefinestheorderinwhichrulesareprocessed.答案:C60.Refertotheexhibits.
TheexhibitsshowtheSSLandauthenticationpolicy(ExhibitA)andthesecuritypolicy(ExhibitB)for
Facebook.
UsersaregivenaccesstotheFacebookwebapplication.TheycanplayvideocontenthostedonFacebookbut
Theyareunabletoleavereactionsonvideosorothertypesofposts.
Whichpartofthepolicyconfigurationmustyouchangetoresolvetheissue?A、MakeSSLinspectionneedstobeadeepcontentinspection.B、ForceaccesstoFacebookusingtheHTTPservice.C、Gettheadditionalapplicationsignaturesarerequiredtoaddtothesecuritypolicy.D、AddFacebookintheURLcategoryinthesecuritypolicy.答案:A61.Refertotheexhibit.Theexhibitcontainsanetworkinterfaceconfiguration,firewallpolicies,andaCLIconsoleconfiguration.HowwillFortiGatehandleuserauthenticationfortrafficthatarrivesontheLANinterface?A、Ifthereisafull-throughpolicyinplace,userswillnotbepromptedforauthentication.B、UsersfromtheSalesgroupwillbepromptedforauthenticationandcanauthenticatesuccessfullywiththecorrectcredentials.C、Authenticationisenforcedatapolicylevel;alluserswillbepromptedforauthentication.D、UsersfromtheHRgroupwillbepromptedforauthenticationandcanauthenticatesuccessfullywiththecorrectcredentials.答案:C62.Refertotheexhibit.AnetworkadministratoristroubleshootinganIPsectunnelbetweentwoFortiGatedevices.Theadministratorhasdeterminedthatphase1.statusisup.butphase2.failstoeup.Basedonthephase2.configurationshownintheexhibit,whatconfigurationchangewillbringphase2.up?A、OnHQ-FortiGate,enableAuto-negotiate.B、OnRemote-FortiGate,setSecondsto43200.C、OnHQ-FortiGate,enableDiffie-HellmanGroup2.D、OnHQ-FortiGate,setEncryptiontoAES256.答案:D63.IftheIssuerandSubjectvaluesarethesameinadigitalcertificate,whichtypeofentitywasthecertificate
Issuedto?A、ACRLB、ApersonC、AsubordinateCAD、ArootCA答案:D64.AnadministratorwantstoconfigureDeadPeerDetection(DPD)onIPSECVPNfordetectingdeadtunnels.TherequirementisthatFortiGatesendsDPDprobesonlywhennotrafficisobservedinthetunnel.WhichDPDmodeonFortiGatewillmeettheaboverequirement?A、DisabledB、OnDemandC、EnabledD、OnIdle答案:D65.Examinethisoutputfromadebugflow:WhydidtheFortiGatedropthepacket?A、Thenext-hopIPaddressisunreachable.B、ItfailedtheRPFcheck.C、ItmatchedanexplicitlyconfiguredfirewallpolicywiththeactionDENY.D、Itmatchedthedefaultimplicitfirewallpolicy.答案:D66.TheHTTPinspectionprocessinwebfilteringfollowsaspecificorderwhenmultiplefeaturesareenabledinthewebfilterprofile.WhatordermustFortiGateusewhenthewebfilterprofilehasfeaturesenabled,suchassafesearch?A、DNS-basedwebfilterandproxy-basedwebfilterB、StaticURLfilter,FortiGuardcategoryfilter,andadvancedfiltersC、Staticdomainfilter,SSLinspectionfilter,andexternalconnectorsfiltersD、FortiGuardcategoryfilterandratingfilter答案:B67.Refertotheexhibit,whichcontainsaradiusserverconfiguration.
AnadministratoraddedaconfigurationforanewRADIUSserver.Whileconfiguring,the
AdministratorselectedtheIncludeineveryusergroupoption.
WhatwillbetheimpactofusingIncludeineveryusergroupoptioninaRADIUSconfiguration?A、ThisoptionplacestheRADIUSserver,andalluserswhocanauthenticateagainstthatserver,intoeveryFortiGateusergroup.B、ThisoptionplacesallFortiGateusersandgroupsrequiredtoauthenticateintotheRADIUSserver,which,inthiscase,isFortiAuthenticator.C、ThisoptionplacesallusersintoeveryRADIUSusergroup,includinggroupsthatareusedfortheLDAPserveronFortiGate.D、ThisoptionplacestheRADIUSserver,andalluserswhocanauthenticateagainstthatserver,intoeveryRADIUSgroup.答案:A68.Whichstatementiscorrectregardingtheuseofapplicationcontrolforinspectingwebapplications?A、Applicationcontrolcanidentitychildandparentapplications,andperformdifferentactionsonthem.B、Applicationcontrolsignaturesareorganizedinanonhierarchicalstructure.C、ApplicationcontroldoesnotrequireSSLinspectiontoidentitywebapplications.D、Applicationcontroldoesnotdisplayareplacementmessageforablockedwebapplication.答案:A69.Inanexplicitproxysetup,whereistheauthenticationmethodanddatabaseconfigured?A、ProxyPolicyB、AuthenticationRuleC、FirewallPolicyD、Authenticationscheme答案:D70.HowdoesFortiGateactwhenusingSSLVPNinwebmode?A、FortiGateactsasanFDSserver.B、FortiGateactsasanHTTPreverseproxy.C、FortiGateactsasDNSserver.D、FortiGateactsasrouter.答案:B71.WhydoesFortiGatekeepTCPsessionsinthesessiontableforsomesecondsevenafterbothsides
(clientandserver)haveterminatedthesession?A、ToremovetheNAToperation.B、TogeneratelogsC、Tofinishanyinspectionoperations.D、Toallowforout-of-orderpacketsthatcouldarriveaftertheFIN/ACKpackets.答案:D72.Examinethenetworkdiagramshownintheexhibit,then答案thefollowingquestion:WhichoneofthefollowingroutesisthebestcandidaterouteforFGT1.toroutetrafficfromtheWorkstationtotheWebserver?A、/16.[50/0]via,port2.[5/0]B、/0.[20/0]via,port2.C、/30.isdirectlyconnected,port2.D、/24.isdirectlyconnected,port1.答案:D73.Anorganization'semployeeneedstoconnecttotheofficethroughahigh-latencyinternetconnection.WhichSSLVPNsettingshouldtheadministratoradjusttopreventtheSSLVPNnegotiationfailure?A、Changethesession-ttl.B、Changethelogintimeout.C、Changetheidle-timeout.D、Changetheudpidletimer.答案:B74.Whenafirewallpolicyiscreated,whichattributeisaddedtothepolicytosupportrecordinglogstoa
FortiAnalyzeroraFortiManagerandimprovesfunctionalitywhenaFortiGateisintegratedwiththese
Devices?A、LogIDB、UniversallyUniqueIdentifierC、PolicyIDD、SequenceID答案:B75.AnadministratorhasconfiguredoutgoingInterfaceanyinafirewallpolicy.Whichstatementistrueaboutthepolicylistview?A、Policylookupwillbedisabled.B、BySequenceviewwillbedisabled.C、SearchoptionwillbedisabledD、InterfacePairviewwillbedisabled.答案:D76.WhichsecurityfeaturedoesFortiGateprovidetoprotectserverslocatedintheinternalnetworksfromattackssuchasSQLinjections?A、DenialofServiceB、WebapplicationfirewallC、AntivirusD、Applicationcontrol答案:B77.Whatistheeffectofenablingauto-negotiateonthephase2.configurationofanIPsectunnel?A、FortiGateautomaticallynegotiatesdifferentlocalandremoteaddresseswiththeremotepeer.B、FortiGateautomaticallynegotiatesanewsecurityassociationaftertheexistingsecurityassociationexpires.C、FortiGateautomaticallynegotiatesdifferentencryptionandauthenticationalgorithmswiththeremotepeer.D、FortiGateautomaticallybringsuptheIPsectunnelandkeepsitup,regardlessofactivityontheIPsectunnel.答案:D78.WhichCLImandwilldisplaysessionsbothfromclienttotheproxyandfromtheproxytotheservers?A、diagnosewadsessionlistB、diagnosewadsessionlist|grephook-pre&&hook-outC、diagnosewadsessionlist|grephook=pre&&hook=outD、diagnosewadsessionlist|grep"hook=pre"&"hook=out"答案:A79.Refertotheexhibits.
AnadministratorcreatesanewaddressobjectontherootFortiGate(Local-FortiGate)inthesecurityfabric.
Aftersynchronization,thisobjectisnotavailableonthedownstreamFortiGate(ISFW).
Whatmusttheadministratordotosynchronizetheaddressobject?A、ChangethecsfsettingonLocal-FortiGate(root)tosetconfiguration-synclocal.B、ChangethecsfsettingonISFW(downstream)tosetconfiguration-synclocal.C、ChangethecsfsettingonLocal-FortiGate(root)tosetfabric-object-unificationdefault.D、ChangethecsfsettingonISFW(downstream)tosetfabric-object-unificationdefault.答案:C80.Refertoexhibit.
Anadministratorconfiguredthewebfilteringprofileshownintheexhibittoblockaccesstoallsocial
NetworkingsitesexceptTwitter.However,whenuserstrytoaccesstwitter.,theyareredirectedtoa
FortiGuardwebfilteringblockpage.
Basedontheexhibit,whichconfigurationchangecantheadministratormaketoallowTwitterwhileblocking
Allothersocialnetworkingsites?A、OntheFortiGuardCategoryBasedFilterconfiguration,setActiontoWarningforSocial
NetworkingB、OntheStaticURLFilterconfiguration,setTypetoSimpleC、OntheStaticURLFilterconfiguration,setActiontoExempt.D、OntheStaticURLFilterconfiguration,setActiontoMonitor.答案:C81.WhydoesFortiGateKeepTCPsessionsinthesessiontableforseveralseconds,evenafter
Bothsides(clientandserver)haveterminatedthesession?A、Toallowforout-of-orderpacketsthatcouldarriveaftertheFIN/ACKpacketsB、TofinishanyinspectionoperationsC、ToremovetheNAToperationD、Togeneratelogs答案:A82.HowdoesFortiGateactwhenusingSSLVPNinwebmode?A、FortiGateactsasanFDSserver.B、FortiGateactsasanHTTPreverseproxy.C、FortiGateactsasDNSserver.D、FortiGateactsasrouter.答案:B83.Refertotheexhibit.
AnetworkadministratoristroubleshootinganIPsectunnelbetweentwoFortiGatedevices.Theadministrator
Hasdeterminedthatphase1statusisup,butphase2failstoeup.
Basedonthephase2configurationsh
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網頁內容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
- 4. 未經權益所有人同意不得將文件中的內容挪作商業(yè)或盈利用途。
- 5. 人人文庫網僅提供信息存儲空間,僅對用戶上傳內容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內容本身不做任何修改或編輯,并不能對任何下載內容負責。
- 6. 下載文件中如有侵權或不適當內容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 船舶泵機租賃合同
- 醫(yī)療創(chuàng)新項目管理流程
- 智能機場智能化施工合同
- 住院期間患者離院管理
- 建筑綠化安全合同協(xié)議書
- 醫(yī)保業(yè)務數據
- 植物園水電設施施工協(xié)議
- 電力工程皮卡租賃協(xié)議
- 醫(yī)療器械招標評分索引表模板
- 神經外科護理觀察典型案例
- 食材配送服務方案(技術方案)
- 生物 七年級 人教版 生物體的結構層次 單元作業(yè)設計
- 小學英語-My father has short hair教學課件設計
- Unit4+Understanding+Ideas+Click+for+a+friend 高中英語外研版(2019)必修第一冊
- 新教科版科學六年級上冊期末綜合測試卷(五)
- HACCP風險評估報告樣板
- 便攜式野外凈水器設計
- 因孩子上學房子過戶協(xié)議書
- 幼兒園課程審議制度
- 大學生就業(yè)指導-面試技巧課件
- 建設工程第三方質量安全巡查標準
評論
0/150
提交評論