NSE8_812 Exam Questions
208 real NSE8_812 exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #151
A company wants to protect against Denial of Service attacks and has launched a new project. They want to block DoS attacks that go above a certain threshold and for some others th...
- Question #152
The output shown on the exhibit from FortiManager is displayed during an import if the device configuration. Which statement describes the correct action taken for these duplicate...
- Question #153
Your FortiGate has multiple CPUs. You want to verify the load for each CPU. Which two commands will accomplish this task? (Choose two.)
- Question #154
You are investigating a problem related to FTP active mode. You use a test PC with IP address 10.100.60.5 to connect to the FTP server at 172.16.133.50 and transfer a large file. T...
- Question #155
Which of the following statements about LACP on FortiGate hardware acceleration is true?
- Question #156
Referring to the command output shown on the exhibit, how many hosts are connected to the FortiGate?
- Question #157
The wireless controller diagnostic output is shown on the exhibit. Which three statements are true? (Choose three.)
- Question #158
You are installing a new FortiAP as shown on the exhibit, however, the FortiAP cannot discover the FortiGate. The FortiAP obtained an IP from the DHCP server and is reachable. Whic...
- Question #159
You are asked to implement a wireless network for a conference center and need to provision a large number of access points to support a large number of wireless client connections...
- Question #160
Refer to the exhibit for a FortiNAC configuration. In this scenario, which two statements are correct? (Choose two.)
- Question #161
A FortiGate must be configured to accept VoIP traffic which will include session initiation protocol (SIP) traffic. Which statement about the VoIP configuration options is correct?
- Question #162
You have configured a Site-to-Site IPsec VPN tunnel between a FortiGate and a third-party device but notice that one of the error counters on the tunnel interface keeps increasing....
- Question #163
A FortiGate deployment contains the following configuration: config system vdom-exception edit 1 set object router.route-map set scope inclusive set vdom SERVICES next end What is...
- Question #164
Refer to the exhibit. You need to create a base SD-WAN configuration that includes SD-WAN rules and Performance SLAs for spoke sites with various connectivity types. It needs to be...
- Question #165
Which two types of interface have built-in active bypass in FortiDDoS devices? (Choose two.)
- Question #166
An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the Online C...
- Question #167
A Hub FortiGate is connecting multiple branch FortiGate devices separating the traffic centrally in unique VRFs. Routing information is exchanged using BGP between the Hub and the...
- Question #168
Refer to the exhibit. Given the exhibit, which two statements about FortiGate FGSP HA cluster behavior are correct? (Choose two.)
- Question #169
Refer to the exhibit showing a FortiView monitor screen. After a Secure SD-WAN implementation, a customer reports that in FortiAnalyzer under FortiView Secure SD-WAN Monitor there...
- Question #170
Which configuration caused the IPS engine to generate this log? [log snippet showing event-type="signature" level="information" msg="**appin-44569** srcip=10.1.10.100... ]
- Question #171
Refer to the exhibit. You are managing a FortiSwitch 3032E that is managed by FortiLink on a FortiGate 3960E. The 3032E is heavily utilized and there is only one port free. The req...
- Question #172
A customer has FortiAP devices in three branch offices managed from a FortiGate in the HQ. Each FortiAP is connected to a dedicated management VLAN. The customer wants the users co...
- Question #173
Refer to the exhibit showing a FortiEDR configuration. Based on the exhibit, which statement is correct?
- Question #174
You are performing a packet capture on a FortiGate 2600F with the hyperscale licensing installed. You need to display on screen all egress/ingress packets from the port16 interface...
- Question #175
The exhibits show the configuration and debug output from a FortiGate Public SDN Connector. What is a possible reason for this dynamic address object to be empty?
- Question #176
A customer needs to create a multi-tier MCLAG set up with the topology as shown in the exhibit. Which command snippet should be applied to it, to allow active/active links in this...
- Question #177
A customer wants to automate the creation and configuration of FortiGate VM instances in a VMware vCenter environment using Terraform. They have the creation part with working code...
- Question #178
You deployed a fully loaded FG-7121F in the data center and enabled sslvpn-load-balance. Based on the behavior of this feature which statement is correct?
- Question #179
A customer is operating a FortiWeb cluster in a high volume active-active HA group consisting of eight FortiWeb appliances. One of the secondary members is handling traffic for one...
- Question #180
An administrator discovers that CPU utilization of a FortiGate-200F is high and determines that no traffic is being accelerated by hardware. Why is no traffic being accelerated by...
- Question #181
A customer would like to improve the performance of a FortiGate VM running in an Azure D4s_v3 instance, but they already purchased a BYOL VM04 license. Which two actions will impro...
- Question #182
Refer to the exhibit. An HTTPS access proxy is configured to demonstrate its function as a reverse proxy on behalf of the web server it is protecting. It verifies user identity, de...
- Question #183
A customer in Costa Rica has a FortiGate with SD-WAN configured to use a VPN connection to the United States to browse the internet using a public IP from that country. They would...
- Question #184
The exhibit shows the topology a customer wants to implement using a flexible authentication scheme. Users connecting from trusted remote locations are authenticated using only the...
- Question #185
Based on the Server Policy settings shown in the exhibit, which two configuration changes will resolve this issue? (Choose two.) A. Disable Redirect HTTP to HTTPS in the Server Pol...
- Question #186
The VPN tunnel between headquarters and the branch office is not being established. What is causing the problem? A. The Phase-1 encryption algorithm are not matching. B. There is a...
- Question #187
Given this scenario, which two statements are true? (Choose two.) A. If iBGP is used, cross-regional spoke-to-hub shortcuts can be established. B. If eBGP is used, ADVPN can be est...
- Question #188
A customer wants to use SD-WAN for traffic generated from the data center towards Branches. SD-WAN on HUB should follow the underlay condition on each Branch and the solution shoul...
- Question #189
Refer to the exhibits, which show a topology and diagnostic commands. Which two statements about the path resolution are true? (Choose two.) A. Latency is the quality criteria. B....
- Question #190
Which two statements about bounce address tagging and verification (BATV) on FortiMail are true? (Choose two.) A. You must publish the BATV public key as a DNS TXT record. B. Email...
- Question #191
Refer to the exhibits. Exhibit A displays FortiGate device settings, including the meta field `data_subnet_fgt_ip` set to `10.10.1.9`. Exhibit B provides CLI commands for a DHCP se...
- Question #192
Refer to the exhibit, which shows an SD-WAN configuration for Branch1, including a `config duplication` block with `set dstintf "HUB1" "HUB1-BKP"`. You configured SD-WAN from Branc...
- Question #193
corresponding to the SD-WAN setup. What is the problem in this scenario?
- Question #194
QUESTION 226 Refer to the exhibit. What is happening in this scenario?
- Question #195
QUESTION 227 Refer to the exhibits showing troubleshooting session output and VPN configuration details. A customer is trying to restore a VPN connection configured on a FortiGate....
- Question #196
QUESTION 228 A FortiGate running FortiOS 7.2.0 GA is configured in multi-vdom mode with a vdom set to vdom type Admin and another vdom set to vdom type Traffic. Which two GUI secti...
- Question #197
A customer is trying to setup a Playbook automation using a FortiAnalyzer, FortiWeb and FortiGate. The intention is to have the FortiGate quarantine any source of SQL Injection det...
- Question #198
A FortiGate is configured to perform outbound firewall authentication with Azure AD as a SAML IdP. What are two valid interactions that occur when the client attempts to access the...
- Question #199
In this scenario, which outcome is true regarding the "subnet_1" firewall address object on FGTC?
- Question #200
A network administrator has been tasked with modifying the existing dial-up IPsec VPN infrastructure to detect the path quality to the remote endpoints. After applying the configur...