10 free sample questions from a bank of 50, with the correct answers and explanations. No signup required — start practising right now.
1Refer to the exhibit. Examine the FortiGate user group configuration and the Windows AD LDAP group membership information shown in the exhibit.
FortiGate is configured to authenticate SSL VPN users against Windows AD using LDAP. The administrator configured the SSL VPN user group for SSL VPN users. However, the administrator noticed that both the t and student and jsmith users can connect to SSL VPN.
Which change can the administrator make on FortiGate to restrict the SSL VPN service to the student user only?
In the SSL VPN user group configuration, set Group Name to CN=SSLVPN,CN=Users,DC=trainingAD,DC=training,DC=lab.
In the SSL VPN user group configuration, change Name to CN=SSLVPN,CN=Users,DC=trainingAD,DC=training,DC=lab.
In the SSL VPN user group configuration, set Group Name to CN=Domain Users,CN=Users,DC=trainingAD,DC=training,DC=lab.
In the SSL VPN user group configuration, change Type to Fortinet Single Sign-On (FSSO).
Answer: A
2Refer to the exhibits. In the wireless configuration shown in the exhibits, an AP is deployed in a remote site and has a wireless network (VAP) called Corporate deployed to it.
The network is a tunnelled network; however, clients connecting to a wireless network require access to a local printer. Clients are trying to print to a printer on the remote site, but are unable to do so.
Which configuration change is required to allow clients connected to the Corporate SSID to print locally?
Configure split-tunneling in the vap configuration.
Configure split-tunneling in the wtp-profile configuration.
Disable the Block Intra-SSID Traffic (Intra-vap-privacy) setting on the SSID (VAP) profile.
Configure the printer as a wireless client on the Corporate wireless network.
Answer: A
3Which EAP method requires the use of a digital certificate on both the server end and the client end?
EAP-TTLS
PEAP
EAP-GTC
EAP-TLS
Answer: D
4Refer to the exhibit. Examine the FortiManager configuration and FortiGate CLI output shown in the exhibit.
An administrator is testing the NAC feature. The test device is connected to a managed FortiSwitch device (S224EPTF19005867) on port2.
After applying the NAC policy on port2 and generating traffic on the test device, the test device is not matching the NAC policy; therefore, the test device remains in the onboarding VLAN.
Based on the information shown in the exhibit, which two scenarios are likely to cause this issue? (Choose two.)
Management communication between FortiGate and FortiSwitch is down.
The MAC address configured on the NAC policy is incorrect.
The device operating system detected by FortiGate is not Linux.
Device detection is not enabled on VLAN 4089.
Answer:
5Which two pieces of information can the diagnose test authserver ldap command provide? (Choose two.)
It displays whether the admin bind user credentials are correct.
It displays whether the user credentials are correct.
It displays the LDAP codes returned by the LDAP server.
It displays the LDAP groups found for the user.
Answer:
6You are setting up an SSID (VAP) to perform RADIUS-authenticated dynamic VLAN allocation.
Which three RADIUS attributes must be supplied by the RADIUS server to enable successful VLAN allocation? (Choose three.)
Tunnel-Private-Group-ID
Tunnel-Pvt-Group-ID
Tunnel-Preference
Tunnel-Type
Tunnel-Medium-Type
Answer:
7Refer to the exhibit. Examine the FortiManager information shown in the exhibit.
Which two statements about the FortiManager status are true? (Choose two.)
FortiSwitch manager is working in per-device management mode.
FortiSwitch is not authorized.
FortiSwitch manager is working in central management mode.
FortiSwitch is authorized and offline.
Answer:
8An administrator is testing the connectivity for a new VLAN. The devices in the VLAN are connected to a FortiSwitch device that is managed by FortiGate. Quarantine is disabled on FortiGate.
While testing, the administrator noticed that devices can ping FortiGate and FortiGate can ping the devices. The administrator also noticed that inter-VLAN communication works. However, intra-VLAN communication does not work.
Which scenario is likely to cause this issue?
The native VLAN configured on the ports is incorrect.
The FortiSwitch MAC address table is missing entries.
The FortiGate ARP table is missing entries.
Access VLAN is enabled on the VLAN.
Answer: D
9Refer to the exhibit. By default, FortiOS creates the following DHCP server scope for the FortiLink interface as shown in the exhibit.
What is the objective of the vci-string setting?
To ignore DHCP requests coming from FortiSwitch and FortiExtender devices
To reserve IP addresses for FortiSwitch and FortiExtender devices
To restrict the IP address assignment to FortiSwitch and FortiExtender devices
To restrict the IP address assignment to devices that have FortiSwitch or FortiExtender as their hostname
Answer: C
10An administrator has configured an SSID in bridge mode for corporate employees. All APs are online and provisioned using default AP profiles. Employees are unable to locate the SSID to connect.
Which two configurations can the administrator verify? (Choose two.)
Verify that the broadcast SSID option is enabled in the SSID configuration.
Verify that the Block Intra-SSID Traffic (Intra-vap-privacy) option in the SSID configuration is disabled.
Verify that the SSID to an AP group that should be broadcasting the SSID is applied.
Verify that the SSID is manually applied on AP profiles for both 2.4 GHz and 5 GHz radios.