최신 Fortinet Network Security Expert NSE8_811 무료샘플문제:
1. An old router has been replaced by a FortiWAN device. The FortiWAN has inherited the router's management IP address and now the network administrator needs to remove the old router from the FortiSIEM configuration.
Which two statements are true about this operation? (Choose two.)
A) FortiSIEM will discover a new device for the FortiWAN with the same IP.
B) FortiSIM will move the old router device into the Decommission folder.
C) The old router will be completely deleted from FortiSIEM's CMDB.
D) FotiSEIM needs a special syslog for FortiWAN.
2. Anti-Virus Real-Time Protection is enabled without any exclusions.
Referring to the exhibit, which two behaviors will the FortiClient endpoint have after receiving the profile update from the FortiClient EMS? (Choose two.)
A) If the Real-Time Protection does not detect a virus, the user will be able to access a downloaded file when the FortiSandbox is unreachable.
B) Access to a downloaded file will always be allowed after 60 seconds when the FortiSandbox is reachable.
C) The user will not be able to access a downloaded file for a maximum of 60 seconds if it is not a virus and the FortiSandbox is reachable.
D) Files executed from a mapped network drive will not be inspected by the FortiClient endpoint AntiVirus
engine.
3. Click the Exhibit button.
Click the Exhibit button.
A FortiGate with the default configuration is deployed between two IP phones. FortiGate receives the INVITE request shown in the exhibit form Phone A (internal)to Phone B (external). Which two actions are taken by the FortiGate after the packet is received? (Choose two.)
A) A pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49169 and 49170.
B) The phone A IP address will be translated lo the WAN IP address in all INVITE header fields and the m: field of the SDP statement.
C) a pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49l70 and 49171.
D) The phone A IP address will be translated for the WAN IP address in all INVITE header fields and the SDP statement remains intact.
4. A company has just deployed a new FortiMail in gateway mode. The administrator is asked to strengthen e-mail protection by applying the policies shown below.
- E-mails can only be accepted if a valid e-mail account exists.
- Only authenticated users can send e-mails out
Which two actions will satisfy the requirements? (Choose two. )
A) Configure access control rules.
B) Configure outbound recipient policies.
C) Configure recipient address verification.
D) Configure inbound recipient policies.
5. You deploy a FortiGate device in a remote office based on the requirements shown below.
-- Due to company's security policy, management IP of your FortiGate is not allowed to access the Internet.
-- Apply Web Filtering, Antivirus, IPS and Application control to the protected subnet.
-- Be managed by a central FortiManager in the head office.
Which action will help to achieve the requirements?
A) Configure a default route and make sure that the FortiGate device can pmg to service fortiguard net.
B) Configure FortiGate to use FortiGuard Filtering Port 8888.
C) Configure the FortiGuard override server and use the IP address of service, fortiguard net.
D) Configure the FortiGuard override server and use the IP address of the FortiManager
질문과 대답:
질문 # 1 정답: A,B | 질문 # 2 정답: A,C | 질문 # 3 정답: B,C | 질문 # 4 정답: A,C | 질문 # 5 정답: D |