NSE8_810 Exam Questions
56 real NSE8_810 exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
Click the Exhibit button. You are working on an entry level model FortiGate that has been configured in flow-based inspection mode with various settings optimized for performance....
- Question #2
Click the Exhibit button. Referring to the exhibit, which two statements are true? (Choose two.)
- Question #3
Click the Exhibit button. You created a custom health-check for your FortiWeb deployment. Referring to the output shown in the exhibit, which statement is true?
- Question #4
A company has just deployed a new FortiMail in gateway mode. The administrator is asked to strengthen e-mail protection by applying the policies shown below. -E-mail can only be ac...
- Question #5
Click the Exhibit button. the same Layer 2 segment. What would be configured on the FortiGates on each DC to allow such connectivity?
- Question #6
Click the Exhibit button. You configured an IPsec tunnel to a branch office. Now you want to make sure that the encryption of the tunnel is offloaded to hardware. Referring to the...
- Question #7
You want to access the JSON API on FortiManager to retrieve information on an object. In this scenario, which two methods will satisfy the requirement? (Choose two.)
- Question #8
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device's Web GUI is accessed. You cannot seem to create a f...
- Question #9
Click the Exhibit button. A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it. However, FortiGates A and B have problems connecti...
- Question #10
Click the Exhibit button. The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb. Which statement represents the purpose of this policy?
- Question #11
You want to manage a FortiGate with the FortiCloud service. The FortiGate shows up in your list of devices on the FortiGate Web Site, but all management functions are either missin...
- Question #12
FortiMail is configured with the protected domain "internal.lab". Which two envelope addresses will need an access control rule to relay e-mail sent for unauthenticated users? (Cho...
- Question #14
Click the Exhibit button. You log into FortiManager, look at the Device Manager window and notice that one of your managed devices is not in normal status. Referring to the exhibit...
- Question #15
A FortiOS device is used for termination of VPNs for a number of remote spoke VPN units (designated Group A spokes) using a phase 1 main mode dial-up tunnel using pre-shared keys....
- Question #16
Click the Exhibit button. Referring to the exhibit, which two statements are true about local authentication? (Choose two.)
- Question #17
Click the exhibit. You created an aggregate interface between your FortiGate and a switch consisting of two 1 Gbps links as shown in the exhibit. However, the maximum bandwidth nev...
- Question #18
Click the Exhibit button. You are trying to configure Link-Aggregation Group (LAG), but ports A and B do not appear on the list of member options. Referring to the exhibit, which s...
- Question #19
Click to the Exhibit button. You need to apply the security features below to the network shown in the exhibit. -high grade DDoS protection -Web security and load balancing for Ser...
- Question #20
Click the Exhibit button. An Administrator reports continuous high CPU utilization on a FortiGate device due to the IPS engine. The exhibit shows the global IPS configuration. Whic...
- Question #22
You are building a FortiGate cluster which is stretched over two locations. The HA connections for the cluster are terminated on the local switches in the data centers. Once the Fo...
- Question #23
You cannot ping the FortiGate's default gateway 10.10.10.1 from the FortiGate CLI. The FortiGate's interface facing the default gateway is wan1 and its IP address is 10.10.10.254/2...
- Question #24
You have deployed a FortiGate in NAT/Route mode as a Secure Web Gateway with a few IP-based authentication firewall policies. Your customer reports that some users now have differe...
- Question #25
Click the Exhibit button. The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device. Which two statements are true about the traffic matching...
- Question #27
Click the Exhibit button. You have deployed several perimeter FortiGates with internal segmentation FortiGates behind them. All FortiGate devices are logging to FortiAnalyzer. When...
- Question #28
Click the Exhibit button. Referring to the exhibit, which two behaviors will the FortiClient endpoint have after receiving the profile update from the FortiClient EMS? (Choose two....
- Question #29
You are asked to implement a single FortiGate 5000 chassis using Session-aware Load Balance Cluster (SLBC) with Active - Passive FortinControllers. Both FortiControllers have the c...
- Question #30
Click the Exhibit button. You have configured an HA cluster with two FortiGates. You want to make sure that you are able to manage the individual cluster members directly using por...
- Question #31
Which statement is correct in this scenario?
- Question #32
Click the Exhibit button. A customer has just finished their Azure deployment to secure a Web application behind a FortiGate and a FortiWeb. Now they want to add components to prot...
- Question #33
Click the Exhibit button. Referring to the exhibit, what will happen if FortiSandbox categorizes an e-mail attachment submitted by FortiMail as a high risk?
- Question #34
Click the Exhibit button. Referring to the exhibit, which two statements are true? (Choose two.)
- Question #35
Click the Exhibit button. You configured AV and Web filtering for your outgoing Internet connections. You later noticed that not all Web sessions are being inspected and you start...
- Question #36
Click the Exhibit button. You have two data centers a FortiGate 7000-series chassis connected by VPN, and all traffic flows over an established generic routing encapsulation (GRE)...
- Question #37
Click the Exhibit button. A FortiGate with the default configuration is deployed between two IP phones. FortiGate receives the INVITE request shown in the exhibit form Phone A (int...
- Question #38
You are asked to add a FortiDDoS to the network to combat detected slow connection attacks such as Slowloris. Which prevention mode on FortiDDoS will protect you against this speci...
- Question #39
Click the Exhibit button. The exhibit shows a topology where a FortiGate is split into two VDOMs, root and vd-lan. The root VDOM provides external SSL-VPN access, where the users a...
- Question #41
Click the Exhibit button. Your organization has a FortiGate cluster that is connected to two independent ISPs. You must configure the FortiGate failover for a single ISP failure to...
- Question #42
An old router has been replaced by a FortiWAN device. The FortiWAN has inherited the router's management IP address and now the network administrator needs to remove the old router...
- Question #43
You have a customer experiencing problems with a legacy L3/L4 firewall device and the IPv6 SIP VoIP traffic. Their device is dropping SIP packets, consequently, it cannot process S...
- Question #44
Click the Exhibit button. An administrator implements a multi-chassis link aggregation (MCLAG) solution using two FortiSwitch 448Ds and one FortiGate 3700D. As describes in the net...
- Question #45
Click the Exhibit button. The exhibit shows a full-mesh topology between FortiGates and FortiSwitches. To deploy this configuration, two requirements must be met: -20 Gbps full dup...
- Question #46
Click the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO) and OSPF is used to redistribute routes between the offices. After deployment, a...
- Question #47
You must create a High Availability deployment with two FortiWebs in Amazon Web Services (AWS), each on different Availability Zones (AZ) from the same region. At the same time, ea...
- Question #48
Click the Exhibit button. Only users authenticated in FortiGate-B can reach the server. A customer wants to deploy a single sign-on solution for IPsec VPN users. Once a user is con...
- Question #49
You are administering the FortiGate 5000 and FortiGate 7000 series products. You want to access the HTTPS GUI on the blade located in logical slot 3 of the secondary chassis in a h...
- Question #50
In FortiGate 5000 series, two FortiControllers are working as an SLBC cluster in a-p mode. The configuration shown below is applied. config load-balance session-setup set tcp-ingre...
- Question #51
Click the Exhibit button. Referring to the exhibit, a FortiADC is load balancing IPv4 traffic between two next-hop routers. The FortiADC does not know the IP addresses of the serve...
- Question #52
Click the Exhibit button. Your customer is using dynamic routing to exchange the default route between two FortiGates using OSPFv2. The output of the get router info ospf neighbor...
- Question #53
An organization has one central site and three remote sites. A FortiSIEM has been installed on the central site and now all devices across the remote sites need to be monitored by...
- Question #54
Click the Exhibit button. Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead...