NSE8_812 Exam Questions
208 real NSE8_812 exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51
Which of the following configurations for an OSPF interface is correct?
- Question #52
Which command detects where a routing path is broken?
- Question #53
The exhibit shows an LDAP server configuration on a FortiGate device. The LDAP user, John Smith, has the following LDAP attributes: cn= John Smith OU=CN=John Smith,CN=Users,DC=TAC,...
- Question #54
Your NOC contracts the security team due to a problem with a new application flow. You are instructed to disable hardware acceleration for the policy shown in the exhibit for troub...
- Question #55
Your company uses a cluster of two FortiGate 3600C units in active-passive mode to protect the corporate network. The FortiGate cluster sends its logs to FortiAnalyzer that you hav...
- Question #56
Virtual Domains (VDOMs) allow a FortiGate administrator to do what?
- Question #57Advanced Routing and Switching
A static route is configured for a FortiGate unit from the CLI using the following commands: config router static
static routeCLI configurationFortiGate routing - Question #58
Which of the following conditions is NOT required for this static default route to be displayed in the FortiGate unit's routing table?
- Question #59
A customer wants to install a FortiSandbox device to identify suspicious files received by an e-mail server. All the incoming e-mail traffic to the e-mail server uses the SMTPS pro...
- Question #60
Which statements are correct properties of a partial mesh VPN deployment? (Choose two.)
- Question #61
Which statements are correct regarding an IPv6 over IPv4 IPsec configuration? (Choose two.)
- Question #62
Refer to the exhibit. The exhibit shows a full-mesh deployment between FortiGate and FortiSwitch devices. To deploy this configuration, two requirements must be met: - 20 Gbps full...
- Question #63
You want to manage a FortiGate with the FortiCloud service. The FortiGate shows up in your list of devices on the FortiCloud Web site, but all management functions are either missi...
- Question #64
The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb. Which statement represents the purpose of this policy?
- Question #65
You are asked to add a FortiDDoS to the network to combat detected slow connection attacks such as Slowloris. Which prevention mode on FortiDDoS will protect you against this speci...
- Question #66
You are building a FortiGate cluster which is stretched over two locations. The HA connections for the cluster are terminated on the local switches in the data centers. Once the Fo...
- Question #67
You want to access the JSON API on FortiManager to retrieve information on an object. In this scenario, which two methods will satisfy the requirement? (Choose two.)
- Question #68
You created a custom health-check for your FortiWeb deployment? Given the output shown in the exhibit, which statement is true?
- Question #69
You created an aggregate interface between a FortiGate and a switch consisting of two 1 Gbps links as shown in the exhibit. However, the maximum bandwidth never exceeds 1 Gbps and...
- Question #70
A FortiGate device is configured to authenticate SSL VPN users using digital certificates. A partial FortiGate configuration is shown in the exhibit. Referring to the exhibit, whic...
- Question #71
Which command-line option for deep-inspection SSL would have the FortiGate re-sign all untrusted self- signed certificates with the trusted FortiNet_CA_SSL certificate?
- Question #72
A FortiGate is configured for a dial-up IPsec VPN to allow multiple FortiGate devices to connect to it. However, FortiGate A and B have problems connecting to the VPN. Only one of...
- Question #73
A customer wants to enable SYN flood mitigation in a FortiDDoS device. The FortiDDoS must reply with one SYN/ACK packet per SYN packet from a new source IP address. Which SYN flood...
- Question #74
You configured AV and Web filtering for your outgoing Internet connections. You later notice that not all Web sessions are being inspected and you start troubleshooting the problem...
- Question #75
access the HTTPS GUI of the blade located in logical slot 3 of the secondary chassis in a high-availability cluster. Which URL will accomplish this task?
- Question #76
Given the configuration shown in the exhibit, which two statements are true? (Choose two.)
- Question #77
A customer wants to integrate their on-premise FortiGate with their Azure fabric infrastructure. Which two components must be in place to configure the Azure Fabric connector? (Cho...
- Question #78
You cannot ping the FortiGate default gateway 10.10.10.1 from the FortiGate CLI. The FortiGate interface wan1 and the default gateway is wan1 and its IP address is 10.10.10.254/24....
- Question #79
An organization has one central site and three remote sites. A FortiSIEM has been installed on the central site and now all devices across the remote sites must be centrally monito...
- Question #80
A customer is looking for a way to remove javascripts, macros and hyperlinks from documents traversing the network without affecting the integrity of the content. You propose to us...
- Question #81
Refer to the exhibit. As shown in the exhibit, a FortiADC is load-balancing IPv4 traffic between two next-hop routers. The FortiADC does not know the IP addresses of the servers. A...
- Question #82
You are trying to configure Link-Aggregation Group (LAG), but ports A and B do not appear on the list of member options. Referring to the exhibit, which statement is correct in thi...
- Question #83
You have deployed a FortiGate in NAT/Route mode as a Secure Web Gateway with a few IP-based authentication firewall policies. Your customer reports that some users now have differe...
- Question #84
Refer to the exhibit. In this scenario, which statement is correct?
- Question #85
A customer is experiencing problems with a legacy L3/L4 firewall device and the IPv6 SIP VoIP traffic. Their device is dropping SIP packets; consequently, it cannot process SIP voi...
- Question #86
Refer to the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO). OSPF is used to redistribute routes between the offices. After deployment, a...
- Question #87Advanced Threat Protection and Content Inspection
A customer has a SCADA environmental control device that is triggering a false-positive IPS alert whenever the Web GUI of the device is accessed. You cannot create a functional cus...
IPS false positiveSCADAfirewall policy exemptionSSL inspection - Question #88Infrastructure
Refer to the exhibit. The FortiAP profile used by the FortiGate managed AP is shown in the exhibit. Which two statements in this scenario are correct? (Choose two.)
FortiAP profilewireless radioSSID mappingrogue AP scanning - Question #89Advanced VPN (IPsec, SSL, DMVPN)
Refer to the exhibit. The exhibit shows a topology where a FortiGate is split into two VDOMs, `root` and `vd-lan`. The `root` VDOM provides external SSL-VPN access, where the users...
VDOMSSL-VPNFSSORSSO - Question #90
A customer wants to use a central RADIUS server for management authentication when connecting to the FortiGate GUI and to provide different levels of access for different types of...
- Question #91
Refer to the exhibit. You need to apply the security features listed below to the network shown in the exhibit. - High-grade DDoS protection - Web security and load balancing for S...
- Question #92
In a FortiGate 5000 series, two FortiControllers are working as an SLBC cluster in a-p mode. The configuration shown below is applied: config load-balance session-setup set tcp-ing...
- Question #93
An administrator reports continuous high CPU utilization on a FortiGate device due to the IPS engine. Consider the global IPS configuration shown below. config ips settings set pac...
- Question #94
Refer to the exhibit. You have configured an IPsec tunnel to a branch office. Now you want to make sure that the encryption of the tunnel is offloaded to hardware. Referring to the...
- Question #95
Refer to the exhibit. You have installed a FortiSandbox and configured it in your FortiMail. Referring to the exhibit, which two statements are correct? (Choose two.)
- Question #96
A FortiGate with the default configuration shown below is deployed between two IP telephones. FortiGate receives the INVITE request shown in the exhibit from Phone A (internal) to...
- Question #97
Referring to the exhibit, which statement is true?
- Question #98
A customer is using dynamic routing to exchange the default route between two FortiGate devices using OSPFv2. The output of the get router info ospf neighbor command shows that the...
- Question #99
Referring to the firewall polices shown in exhibit, which two statements are true? (Choose two.)
- Question #100
Referring to the exhibit, what will happen if FortiSandbox categorizes an e-mail attachment submitted by FortiMail as a high risk?