Which of the following conditions must be met in order for a web browser to trust a web server certificate sig
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA? A. The public key of the web server certificate must be installed on the browser. B. The web-server certificate must be installed on the browser. C. The CA certificate that […]
Which statement is true regarding SSL VPN timers? (Choose two.)
Which statement is true regarding SSL VPN timers? (Choose two.) A. Allow to mitigate DoS attacks from partial HTTP requests. B. SSL VPN settings do not have customizable timers. C. Disconnect idle SSL VPN users when a firewall policy authentication timeout occurs. D. Prevent SSL VPN users from being logged out because of high network […]
An administrator wants to block HTTP uploads. Examine the exhibit, which contains the proxy address created fo
An administrator wants to block HTTP uploads. Examine the exhibit, which contains the proxy address created for that purpose. Where must the proxy address be used? A. As the source in a firewall policy. B. As the source in a proxy policy. C. As the destination in a firewall policy. D. As the destination in […]
Which statement is true regarding the policy ID number of a firewall policy?
Which statement is true regarding the policy ID number of a firewall policy? A. Defines the order in which rules are processed. B. Represents the number of objects used in the firewall policy. C. Required to modify a firewall policy using the CLI. D. Changes when firewall policies are reordered.
Based on this output, which statements are correct? (Choose two.)
View the exhibit. Based on this output, which statements are correct? (Choose two.) A. The all VDOM is not synchronized between the primary and secondary FortiGate devices. B. The root VDOM is not synchronized between the primary and secondary FortiGate devices. C. The global configuration is synchronized between the primary and secondary FortiGate devices. D. […]
Which of the following route attributes must be equal for static routes to be eligible for equal cost multipat
Which of the following route attributes must be equal for static routes to be eligible for equal cost multipath (ECMP) routing? (Choose two.) A. Priority B. Metric C. Distance D. Cost
Which statement about FortiGuard services for FortiGate is true?
Which statement about FortiGuard services for FortiGate is true? A. The web filtering database is downloaded locally on FortiGate. B. Antivirus signatures are downloaded locally on FortiGate. C. FortiGate downloads IPS updates using UDP port 53 or 8888. D. FortiAnalyzer can be configured as a local FDN to provide antivirus and IPS updates.
An administrator needs to strengthen the security for SSL VPN access. Which of the following statements are be
An administrator needs to strengthen the security for SSL VPN access. Which of the following statements are best practices to do so? (Choose three.) A. Configure split tunneling for content inspection. B. Configure host restrictions by IP or MAC address. C. Configure two-factor authentication using security certificates. D. Configure SSL offloading to a content processor […]
An administrator has configured central DNAT and virtual IPs. Which of the following can be selected in the fi
An administrator has configured central DNAT and virtual IPs. Which of the following can be selected in the firewall policy Destination field? A. A VIP group B. The mapped IP address object of the VIP object C. A VIP object D. An IP pool
An administrator is investigating a report of users having intermittent issues with browsing the web. The admi
Examine the diagnostic output shown exhibit. Which of the following options is the most likely cause of this issue? A. NAT port exhaustion B. High CPU usage C. High memory usage D. High session timeout value