10 free sample questions from a bank of 118, with the correct answers and explanations. No signup required — start practising right now.
1Examine the FortiGate configuration: What will happen to unauthenticated users when an active authentication policy is followed by a fall through policy without authentication?
The user must log in again to authenticate.
The user will be denied access to resources without authentication.
The user will not be prompted for authentication.
User authentication happens at an interface level.
Answer: A
2When using WPAD DNS method, which FQDN format do browsers use to query the DNS server?
srv_proxy. /wpad.dat
srv_tcp.wpad.
wpad.
proxy. .wpad
Answer: C
3Which statement about a One-to-One IP pool is true?
It is used for destination NAT.
It limits the client to 64 connections per IP pool.
It allows the fixed mapping of an internal address range to an external address range.
It does not use port address translation.
Answer: D
4Refer to the exhibit. The exhibit shows the IPS sensor configuration.
If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)
The sensor will allow attackers matching the NTP.Spoofed.KoD.DoS signature.
The sensor will block all attacks aimed at Windows servers.
The sensor will reset all connections that match these signatures.
The sensor will gather a packet log for all matched traffic.
Answer:
5An administrator wants to throttle the total volume of SMTP sessions to their email server.
Which DoS sensor can the administrator use to achieve this?
ip_src_session
ip_dst_session
udp_flood
tcp_port_scan
Answer: B
6A FortiGate device has multiple VDOMs.
Which statement about an administrator account configured with the default prof_admin profile is true?
It can upgrade the firmware on the FortiGate device.
It can reset the password for the admin account.
It can create administrator accounts with access to the same VDOM.
It cannot have access to more than one VDOM.
Answer: C
7During the digital verification process, comparing the original and fresh hash results satisfies which security requirement?
Signature verification
Authentication
Data integrity
Non-deniability
Answer: C
8Which three statements correctly describe transparent mode operation? (Choose three.)
The transparent FortiGate is visible to network hosts in an IP traceroute.
FortiGate acts as a transparent bridge and forwards traffic at Layer 2.
Ethernet packets are forwarded based on destination MAC addresses, not IP addresses.
It permits inline traffic inspection and firewalling without changing the IP scheme of the network.
All interfaces on the transparent mode FortiGate device must be on different IP subnets.
Answer:
9Which two statements about conserve mode are true? (Choose two.)
Administrators can access the FortiGate only through the console port.
FortiGate stops doing RPF checks over incoming packets.
FortiGate stops sending files to FortiSandbox for inspection.
Administrators cannot change the configuration.
Answer:
10Which two features are supported by web filter in flow-based inspection mode with NGFW mode set to profile-based? (Choose two.)