Fortinet NSE8 - Fortinet Network Security Expert 8 Written Exam Exam
Page: 3 / 13
Total 65 questions
Question #11 (Topic: )
There is an interface-mode IPsec tunnel configured between FortiGate1 and FortiGate2.
You want to run OSPF over the IPsec tunnel. On both FortiGates. the IPsec tunnel is
based on physical interface port1. Port1 has the default MTU setting on both FortiGate
units.
Which statement is true about this scenario?
You want to run OSPF over the IPsec tunnel. On both FortiGates. the IPsec tunnel is
based on physical interface port1. Port1 has the default MTU setting on both FortiGate
units.
Which statement is true about this scenario?
A. A multicast firewall policy must be added on FortiGate1 and FortiGate2 to allow protocol 89.
B. The MTU must be set manually in the OSPF interface configuration.
C. The MTU must be set manually on the IPsec interface.
D. An IP address must be assigned to the IPsec interface on FortiGate1 and FortiGate2.
Answer: B
Question #12 (Topic: )
Which two features are supported only by FortiMail but not by FortiGate? (Choose two.)
A. DNSBL
B. built-in MTA
C. end-to-end IBE encryption
D. FortiGuard Antispam
Answer: A,B
Question #13 (Topic: )
A company has just installed a new FortiGate in their core to route and inspect traffic
between their subnetted VLANs. The security department reports that after the installation,
their IP video cameras no longer work. Research by the IT department shows that the
video system uses a multicast stream to send the video to multiple video receivers.
Which two commands must be configured to resolve this problem? (Choose two.)
between their subnetted VLANs. The security department reports that after the installation,
their IP video cameras no longer work. Research by the IT department shows that the
video system uses a multicast stream to send the video to multiple video receivers.
Which two commands must be configured to resolve this problem? (Choose two.)
A.
B.
C.
D.
Answer: B,D
Question #14 (Topic: )
[Fortinet-NSE8-8.0/Fortinet-NSE8-13_2.png]
The exhibit shows an LDAP server configuration in a FortiGate device. The LDAP user,
John Smith, has the following LDAP attributes:
[Fortinet-NSE8-8.0/Fortinet-NSE8-13_3.png]
John Smiths LDAP password is ABC123.
Which CLI command should you use to test the LDAP authentication using John Smiths
credentials?
The exhibit shows an LDAP server configuration in a FortiGate device. The LDAP user,
John Smith, has the following LDAP attributes:
[Fortinet-NSE8-8.0/Fortinet-NSE8-13_3.png]
John Smiths LDAP password is ABC123.
Which CLI command should you use to test the LDAP authentication using John Smiths
credentials?
A. diagnose test authserver ldap Lab jsmith ABC123
B. diagnose test authserver ldap-direct Lab jsmith ABC123
C. diagnose test authserver ldap Lab ‘John Smith’ ABC123
D. diagnose test authserver ldap-direct Lab john ABC123
Answer: A
Question #15 (Topic: )
Your company uses a cluster of two FortiGate 3600C units in active-passive mode to
protect the corporate network. The FortiGate cluster sends its logs to a FortiAnalyzer and
you have configured scheduled weekly reports for the Internet bandwidth usage of each
corporate VLAN. During a scheduled maintenance window, you make a series of
configuration changes. When the next FortiAnalyzer weekly report is generated, you notice
that Internet bandwidth usage reported by the FortiAnalyzer is far less than expected.
What is the reason for this discrepancy?
protect the corporate network. The FortiGate cluster sends its logs to a FortiAnalyzer and
you have configured scheduled weekly reports for the Internet bandwidth usage of each
corporate VLAN. During a scheduled maintenance window, you make a series of
configuration changes. When the next FortiAnalyzer weekly report is generated, you notice
that Internet bandwidth usage reported by the FortiAnalyzer is far less than expected.
What is the reason for this discrepancy?
A. You applied an antivirus profile on some of the policies, and no traffic can be accelerated.
B. You disabled all security profiles on some of the firewall policies, and the traffic matching those policies is now accelerated.
C. You enabled HA session-pickup, which is turn disabled session accounting.
D. You changed from active-passive to active-active, causing the session traffic counters to become inaccurate.
Answer: D