Fortinet NSE8_810 - Fortinet Network Security Expert 8 Written Exam (NSE8 810 - FortiOS 5.6) Exam
Page: 3 / 12
Total 60 questions
Question #11 (Topic: Topic 1)
You want to manage a FortiGate with the FortiCloud service.
The FortiGate shows up in your list of devices on the FortiGate Web Site, but all management functions are either missing or grayed out. Which statement is
correct in this scenario?
The FortiGate shows up in your list of devices on the FortiGate Web Site, but all management functions are either missing or grayed out. Which statement is
correct in this scenario?
A. The managed FortiGate is running a version of FortiOS that is either too new or too old for FortiCloud.
B. The managed FortiGate requires that a FortiCloud management license be purchased and applied. configure system central-management on the FortiGate CLI and set the management type to fortiguard.
C. You must manually normal.
D. The management tunnel mode on the managed FortiGate must be changed to
Answer: C
Question #12 (Topic: Topic 1)
FortiMail is configured with the protected domain “internal.labâ€.
Which two envelope addresses will need an access control rule to relay e-mail sent for unauthenticated users? (Choose two.)
Which two envelope addresses will need an access control rule to relay e-mail sent for unauthenticated users? (Choose two.)
A. MAIL FROM: [email protected];RCPT TO;[email protected]
B. MAIL FROM: [email protected];RCPT TO;[email protected]
C. MAIL FROM: [email protected];RCPT TO;[email protected]
D. MAIL FROM: student@ internal.lab;RCPT TO;[email protected]
Answer: BC
Question #13 (Topic: Topic 1)
You deploy a FortiGate device in a remote office based on the requirements shown below.
-Due to company’s security policy, management IP of your FortiGate is not allowed to access the Internet.
- Apply Web Filtering, AntiVirus, IPS and Application control to the protected subnet.
- Be managed by a central FortiManager on the head office.
Which action will help to achieve the requirements?
-Due to company’s security policy, management IP of your FortiGate is not allowed to access the Internet.
- Apply Web Filtering, AntiVirus, IPS and Application control to the protected subnet.
- Be managed by a central FortiManager on the head office.
Which action will help to achieve the requirements?
A. Configure a default route and make sure that the FortiGate device can ping to service.fortiguard.net
B. Configure the FortiGuard override server and use the IP address of the FortiManager.
C. Configure the FortiGuard override server and use the IP address of service.fortiguard.net.
D. Configure FortiGuard to use FortiGuard Filtering Port 8888.
Answer: B
Question #14 (Topic: Topic 1)
Click the Exhibit button.
[Fortinet-NSE8-810-1.0/xmlfile-19_1.jpg]
You log into FortiManager, look at the Device Manager window and notice that one of your managed devices is not in normal status.
Referring to the exhibit, which two statements correctly describe the affected device’s status and result? (Choose two.)
[Fortinet-NSE8-810-1.0/xmlfile-19_1.jpg]
You log into FortiManager, look at the Device Manager window and notice that one of your managed devices is not in normal status.
Referring to the exhibit, which two statements correctly describe the affected device’s status and result? (Choose two.)
A. The device configuration was changed on the local FortiGate side only; auto-update is disabled.
B. The device configuration was changed on both the local FortiGate side and the FortiManager side; auto-update is disabled.
C. The changed configuration on the FortiGate will remain the next time that the device configuration is pushed form FortiManager.
D. The changed configuration on the FortiGate will be overwritten in favor of what is on the FortiManager the next time that the device configuration is pushed.
Answer: BD
Question #15 (Topic: Topic 1)
A FortiOS device is used for termination of VPNs for a number of remote spoke VPN units (designated Group A spokes) using a phase 1 main mode dial-up
tunnel using pre-shared keys. Your company recently acquired another organization. You are asked to establish VPN connectivity for the newly acquired
organization’s sites for which new devices will be provisioned (designated Group B spokes). Both existing (Group A) and new (Group B) spoke units are
dynamically addressed. You are asked to ensure that spokes from the acquired organization (Group B) have different access permissions that your existing VPN
spokes units (Group A).
Which two solutions meet the requirements for the new spoke group? (Choose two.)
tunnel using pre-shared keys. Your company recently acquired another organization. You are asked to establish VPN connectivity for the newly acquired
organization’s sites for which new devices will be provisioned (designated Group B spokes). Both existing (Group A) and new (Group B) spoke units are
dynamically addressed. You are asked to ensure that spokes from the acquired organization (Group B) have different access permissions that your existing VPN
spokes units (Group A).
Which two solutions meet the requirements for the new spoke group? (Choose two.)
A. Implement a new phase 1 dial-up main mode tunnel with preshared keys and XAuth. Use identity policies to filter traffic.
B. Implement a new phase 1 dial-up main mode tunnel with a different pre-shared key than Group A spokes. Use standard policies to filter traffic for the new dial- up tunnel.
C. Implement a new phase 1 dial-up main mode tunnel with certificate authentication. Use standard policies to filter traffic for the new dial-up tunnel.
D. Implement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID. Use standard policies to filter traffic for the new dial-up tunnel.
Answer: AB