Q1. - (Topic 2) Review the configuration for FortiClient IPsec shown in the Exhibit below. Which of the following statements is correct regarding this configuration? A. The connecting VPN client will install a route to a destination corresponding to the STUDENT_INTERNAL address object B. The connecting VPN client will install a default route C. The connecting VPN client will install a route to the 172.20.1.[1-5]…
Q1. - (Topic 1) When backing up the configuration file on a FortiGate unit, the contents can be encrypted by enabling the encrypt option and supplying a password. If the password is forgotten, the configuration file can still be restored using which of the following methods? A. Selecting the recover password option during the restore process. B. Having the password emailed to the administrative user…
Q1. - (Topic 3) A network administrator connects his PC to the INTERNAL interface on a FortiGate unit. The administrator attempts to make an HTTPS connection to the FortiGate unit on the VLAN1 interface at the IP address of 10.0.1.1, but gets no connectivity. The following troubleshooting commands are executed from the CLI: user1 # get system interface == [ internal ] namE. internal modE.…
Q1. - (Topic 1) Under the System Information widget on the dashboard, which of the following actions are available for the system configuration? (Select all that apply.) A. Backup B. Restore C. Revisions D. Export View AnswerAnswer: A,B,C Q2. - (Topic 1) Which of the following are valid authentication user group types on a FortiGate unit? (Select all that apply.) A. Firewall B. Directory Service C. Local D. LDAP E. PKI View AnswerAnswer: A,B Q3.…
Q1. - (Topic 2) Two FortiGate devices fail to form an HA cluster, the device hostnames are STUDENT and REMOTE. Exhibit A shows the command output of 'show system ha' for the STUDENT device. Exhibit B shows the command output of 'show system ha' for the REMOTE device. Exhibit A: Exhibit B Which one of the following is the most likely reason that the…
Q1. - (Topic 1) What is the FortiGate unit password recovery process? A. Interupt boot sequence, modify the boot registry and reboot. After changing the password, reset the boot registry. B. Log in through the console port using the maintainer account within several minutes of a reboot. C. Hold CTRL + break during reboot and reset the admin password. D. The only way to regain…
Q1. - (Topic 3) An issue could potentially occur when clicking Connect to start tunnel mode SSL VPN. The tunnel will start up for a few seconds, then shut down. Which of the following statements best describes how to resolve this issue? A. This user does not have permission to enable tunnel mode. Make sure that the tunnel mode widget has been added…
Q1. - (Topic 1) Which of the following is true regarding Switch Port Mode? A. Allows all internal ports to share the same subnet. B. Provides separate routable interfaces for each internal port. C. An administrator can select ports to be used as a switch. D. Configures ports to be part of the same broadcast domain. View AnswerAnswer: A Q2. - (Topic 2) Review the IKE debug output…
Q1. - (Topic 3) A network administrator needs to implement dynamic route redundancy between a FortiGate unit located in a remote office and a FortiGate unit located in the central office. The remote office accesses central resources using IPSec VPN tunnels through two different Internet providers. What is the best method for allowing the remote office access to the resources through the FortiGate…
Q1. - (Topic 3) An organization wishes to protect its SIP Server from call flooding attacks. Which of the following configuration changes can be performed on the FortiGate unit to fulfill this requirement? A. Apply an application control list which contains a rule for SIP and has the "Limit INVITE Request" option configured. B. Enable Traffic Shaping for the appropriate SIP firewall policy. C.…