10 free sample questions from a bank of 103, with the correct answers and explanations. No signup required — start practising right now.
1What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
It limits the scanning of application traffic to the browser-based technology category only.
It limits the scanning of application traffic to the DNS protocol only.
It limits the scanning of application traffic to use parent signatures only.
It limits the scanning of application traffic to the application category only.
Answer: A
2An administrator is configuring an IPsec VPN between site A and site B. The Remote Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192.168.1.0/24 and the remote quick mode selector is 192.168.2.0/24.
Which subnet must the administrator configure for the local quick mode selector for site B?
192.168.2.0/24
192.168.0.0/8
192.168.1.0/24
192.168.3.0/24
Answer: A
3How can you disable RPF checking?
Disable fail-detect on the interface level settings.
Disable strict-src-check under system settings.
Unset fail-alert-interfaces on the interface level settings.
Disable src-check on the interface level settings.
Answer: D
4An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway.
What must the administrator do to achieve this objective?
The administrator must register the same FortiToken on more than one FortiGate device.
The administrator must use the user self-registration server.
The administrator must use a FortiAuthenticator device.
The administrator must use a third-party RADIUS OTP server.
Answer: C
5Refer to the exhibits.
Exhibit A shows a network diagram. Exhibit B shows the central SNAT policy and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow all destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching central SNAT policies will be applied. Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
10.200.1.99
10.200.1.1
10.200.1.49
10.200.1.149
Answer: A
6Refer to the exhibits.
The exhibits contain a network interface configuration, firewall policies, and a CLI console configuration. How will the FortiGate device handle user authentication for traffic that arrives on the LAN interface?
All users will be prompted for authentication; users from the HR group can authenticate successfully with the correct credentials.
If there is a fall-through policy in place, users will not be prompted for authentication.
All users will be prompted for authentication; users from the sales group can authenticate successfully with the correct credentials.
Authentication is enforced only at a policy level; all users will be prompted for authentication.
Answer: A
7Refer to the exhibit.
In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output shown in the exhibit. What should the administrator do next, to troubleshoot the problem?
Execute a debug flow.
Capture the traffic using an external sniffer connected to port1.
Execute another sniffer on FortiGate, this time with the filter "host 10.0.1.10".
Run a sniffer on the web server.
Answer: A
8Which two settings are required for SSL VPN to function between two FortiGate devices? (Choose two.)
The client FortiGate requires a manually added route to remote subnets.
The client FortiGate requires a client certificate signed by the CA on the server FortiGate.
The server FortiGate requires a CA certificate to verify the client FortiGate certificate.
The client FortiGate requires the SSL VPN tunnel interface type to connect SSL VPN.
Answer:
9Which statement correctly describes the use of reliable logging on FortiGate?
Reliable logging is enabled by default in all configuration scenarios.
Reliable logging is required to encrypt the transmission of logs.
Reliable logging can be configured only using the CLI.
Reliable logging prevents the loss of logs when the local disk is full.
Answer: B
10Refer to the exhibits.
The exhibits contain a network diagram, and virtual IP, IP pool, and firewall policies configuration information.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled using IP pool.
The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.1.10?