NSE8_810 Exam Questions
56 real NSE8_810 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1FortiGate ZTA
Click the Exhibit button. You are working on an entry level model FortiGate that has been configured in flow-based inspection mode with various settings optimized for performance....
antivirus profilequick scan modeflow-based inspectionmalware detection - Question #2FortiNAC for ZTA
Click the Exhibit button. Referring to the exhibit, which two statements are true? (Choose two.)
LAGlink aggregationFortiSwitch802.3ad - Question #3ZTA Management and Monitoring
Click the Exhibit button. You created a custom health-check for your FortiWeb deployment. Referring to the output shown in the exhibit, which statement is true?
health checkFortiWebHTTP response codecustom health check - Question #4Zero Trust Access Concepts
A company has just deployed a new FortiMail in gateway mode. The administrator is asked to strengthen e-mail protection by applying the policies shown below. -E-mail can only be ac...
FortiMailrecipient address verificationaccess control rulesemail relay - Question #5FortiGate ZTA
Click the Exhibit button. the same Layer 2 segment. What would be configured on the FortiGates on each DC to allow such connectivity?
IPsec tunnelVXLAN encapsulationLayer 2 connectivityVPN - Question #6FortiGate ZTA
Click the Exhibit button. You configured an IPsec tunnel to a branch office. Now you want to make sure that the encryption of the tunnel is offloaded to hardware. Referring to the...
IPsechardware offloadencryption offloadtunnel performance - Question #7
You want to access the JSON API on FortiManager to retrieve information on an object. In this scenario, which two methods will satisfy the requirement? (Choose two.)
- Question #8FortiGate ZTA
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device's Web GUI is accessed. You cannot seem to create a f...
IPS false positiveSCADAfirewall policy exemptionSSL inspection - Question #9FortiGate ZTA
Click the Exhibit button. A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it. However, FortiGates A and B have problems connecti...
dial-up IPsecroute-overlapmultiple VPN connectionsIKE - Question #10ZTA Management and Monitoring
Click the Exhibit button. The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb. Which statement represents the purpose of this policy?
URL rewriteHTTP to HTTPS redirectFortiWeb policyregex pattern - Question #11ZTA Management and Monitoring
You want to manage a FortiGate with the FortiCloud service. The FortiGate shows up in your list of devices on the FortiGate Web Site, but all management functions are either missin...
FortiCloudcentral managementmanagement tunnelFortiOS CLI - Question #12FortiAuthenticator for ZTA
FortiMail is configured with the protected domain "internal.lab". Which two envelope addresses will need an access control rule to relay e-mail sent for unauthenticated users? (Cho...
FortiMailaccess control relayFortiGuard overrideunauthenticated users - Question #14ZTA Management and Monitoring
Click the Exhibit button. You log into FortiManager, look at the Device Manager window and notice that one of your managed devices is not in normal status. Referring to the exhibit...
FortiManagerdevice statusconfiguration syncauto-update - Question #15FortiGate ZTA
A FortiOS device is used for termination of VPNs for a number of remote spoke VPN units (designated Group A spokes) using a phase 1 main mode dial-up tunnel using pre-shared keys....
dial-up VPNXAuthpeer IDaccess permissions - Question #16FortiAuthenticator for ZTA
Click the Exhibit button. Referring to the exhibit, which two statements are true about local authentication? (Choose two.)
local authenticationlogin failure lockoutIP blockre-authentication timer - Question #17
Click the exhibit. You created an aggregate interface between your FortiGate and a switch consisting of two 1 Gbps links as shown in the exhibit. However, the maximum bandwidth nev...
- Question #18FortiGate ZTA
Click the Exhibit button. You are trying to configure Link-Aggregation Group (LAG), but ports A and B do not appear on the list of member options. Referring to the exhibit, which s...
LAGlink aggregationintegrated switch fabricFortiGate interfaces - Question #19Advanced Threat Protection and Content Inspection
Click to the Exhibit button. You need to apply the security features below to the network shown in the exhibit. -high grade DDoS protection -Web security and load balancing for Ser...
FortiDDoSFortiADCPCI DSS compliancenetwork security architecture - Question #20Advanced Threat Protection and Content Inspection
Click the Exhibit button. An Administrator reports continuous high CPU utilization on a FortiGate device due to the IPS engine. The exhibit shows the global IPS configuration. Whic...
IPS engineCPU optimizationIPS configurationperformance tuning - Question #22High Availability and Resiliency
You are building a FortiGate cluster which is stretched over two locations. The HA connections for the cluster are terminated on the local switches in the data centers. Once the Fo...
HA clusterCRC errorsstretched clusterHA heartbeat - Question #23
You cannot ping the FortiGate's default gateway 10.10.10.1 from the FortiGate CLI. The FortiGate's interface facing the default gateway is wan1 and its IP address is 10.10.10.254/2...
- Question #24Secure Access and Authentication
You have deployed a FortiGate in NAT/Route mode as a Secure Web Gateway with a few IP-based authentication firewall policies. Your customer reports that some users now have differe...
FSSOTerminal Server agentIP-based authenticationRDP - Question #25Advanced Threat Protection and Content Inspection
Click the Exhibit button. The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device. Which two statements are true about the traffic matching...
FortiDDoSSPP configurationSYN flood protectionLIP table - Question #27Centralized Management and Logging
Click the Exhibit button. You have deployed several perimeter FortiGates with internal segmentation FortiGates behind them. All FortiGate devices are logging to FortiAnalyzer. When...
FortiAnalyzer loggingDNS traffic logsapplication controlIPS profile - Question #28Advanced Threat Protection and Content Inspection
Click the Exhibit button. Referring to the exhibit, which two behaviors will the FortiClient endpoint have after receiving the profile update from the FortiClient EMS? (Choose two....
FortiClientFortiSandbox integrationendpoint AVEMS profile - Question #29High Availability and Resiliency
You are asked to implement a single FortiGate 5000 chassis using Session-aware Load Balance Cluster (SLBC) with Active - Passive FortinControllers. Both FortiControllers have the c...
SLBCFortiControllerchassis HAFortiGate 5000 - Question #30
Click the Exhibit button. You have configured an HA cluster with two FortiGates. You want to make sure that you are able to manage the individual cluster members directly using por...
- Question #31Web and Email Security
Which statement is correct in this scenario?
SSL deep inspectionweb filtering categoriesSNIcertificate name - Question #32Centralized Management and Logging
Click the Exhibit button. A customer has just finished their Azure deployment to secure a Web application behind a FortiGate and a FortiWeb. Now they want to add components to prot...
FortiManagerFortiSIEMFortiSandboxAzure deployment - Question #33Web and Email Security
Click the Exhibit button. Referring to the exhibit, what will happen if FortiSandbox categorizes an e-mail attachment submitted by FortiMail as a high risk?
FortiSandboxFortiMailemail attachment quarantinesandbox verdict - Question #34Web and Email Security
Click the Exhibit button. Referring to the exhibit, which two statements are true? (Choose two.)
DNS filteringIPv4 vs IPv6 policysecurity profilesweb filtering - Question #35Web and Email Security
Click the Exhibit button. You configured AV and Web filtering for your outgoing Internet connections. You later noticed that not all Web sessions are being inspected and you start...
SSL inspectionQUIC protocolweb filteringsession inspection - Question #36Network Infrastructure and Core FortiGate Features
Click the Exhibit button. You have two data centers a FortiGate 7000-series chassis connected by VPN, and all traffic flows over an established generic routing encapsulation (GRE)...
FortiGate 7000FPM load balancingGRE tunnelload balance algorithm - Question #37
Click the Exhibit button. A FortiGate with the default configuration is deployed between two IP phones. FortiGate receives the INVITE request shown in the exhibit form Phone A (int...
- Question #38Advanced Threat Protection and Content Inspection
You are asked to add a FortiDDoS to the network to combat detected slow connection attacks such as Slowloris. Which prevention mode on FortiDDoS will protect you against this speci...
FortiDDoSSlowloris attackaggressive aging modeslow connection attack - Question #39Secure Access and Authentication
Click the Exhibit button. The exhibit shows a topology where a FortiGate is split into two VDOMs, root and vd-lan. The root VDOM provides external SSL-VPN access, where the users a...
SSL-VPNVDOM authenticationFSSORADIUS accounting - Question #41Advanced Routing and Switching
Click the Exhibit button. Your organization has a FortiGate cluster that is connected to two independent ISPs. You must configure the FortiGate failover for a single ISP failure to...
BGPBFDgraceful restartISP failover - Question #42Centralized Management and Logging
An old router has been replaced by a FortiWAN device. The FortiWAN has inherited the router's management IP address and now the network administrator needs to remove the old router...
FortiSIEMCMDB managementdevice decommissionFortiWAN - Question #43
You have a customer experiencing problems with a legacy L3/L4 firewall device and the IPv6 SIP VoIP traffic. Their device is dropping SIP packets, consequently, it cannot process S...
- Question #44Network Infrastructure and Core FortiGate Features
Click the Exhibit button. An administrator implements a multi-chassis link aggregation (MCLAG) solution using two FortiSwitch 448Ds and one FortiGate 3700D. As describes in the net...
MCLAGFortiSwitchFortiLink split interfaceLAG - Question #45Network Infrastructure and Core FortiGate Features
Click the Exhibit button. The exhibit shows a full-mesh topology between FortiGates and FortiSwitches. To deploy this configuration, two requirements must be met: -20 Gbps full dup...
MCLAGICLISLFortiLink split interface - Question #46Advanced Routing and Switching
Click the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO) and OSPF is used to redistribute routes between the offices. After deployment, a...
OSPF redistributionIPsec VPNrouting conflictaccess-list - Question #47High Availability and Resiliency
You must create a High Availability deployment with two FortiWebs in Amazon Web Services (AWS), each on different Availability Zones (AZ) from the same region. At the same time, ea...
FortiWeb HAActive-Active HAAWS ELBmulti-AZ - Question #48Secure Access and Authentication
Click the Exhibit button. Only users authenticated in FortiGate-B can reach the server. A customer wants to deploy a single sign-on solution for IPsec VPN users. Once a user is con...
SSOIPsec VPNRADIUS accountingFortiAuthenticator - Question #49High Availability and Resiliency
You are administering the FortiGate 5000 and FortiGate 7000 series products. You want to access the HTTPS GUI on the blade located in logical slot 3 of the secondary chassis in a h...
FortiGate 5000chassis managementHA clusterblade GUI access - Question #50High Availability and Resiliency
In FortiGate 5000 series, two FortiControllers are working as an SLBC cluster in a-p mode. The configuration shown below is applied. config load-balance session-setup set tcp-ingre...
SLBCFortiControllerDP session tableTCP session setup - Question #51
Click the Exhibit button. Referring to the exhibit, a FortiADC is load balancing IPv4 traffic between two next-hop routers. The FortiADC does not know the IP addresses of the serve...
- Question #52Advanced Routing and Switching
Click the Exhibit button. Your customer is using dynamic routing to exchange the default route between two FortiGates using OSPFv2. The output of the get router info ospf neighbor...
OSPFv2default route redistributionrouting prefixOSPF troubleshooting - Question #53Centralized Management and Logging
An organization has one central site and three remote sites. A FortiSIEM has been installed on the central site and now all devices across the remote sites need to be monitored by...
FortiSIEMCollectorWAN optimizationcentralized monitoring - Question #54Network Infrastructure and Core FortiGate Features
Click the Exhibit button. Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead...
Central NATSNAT mapICMP protocolVIP