An administrator sets up a new FTP server on TCP port 2121. A FortiGate unit is located between the FTP clients and the server. The administrator has created a policy for TCP port 2121.
Users have been complaining that when downloading data they receive a 200 Port command successful message followed by a 425 Cannot build data connection message.
Which of the following statements represents the best solution to this problem?
A. Place the client and server interface in the same zone and enable intra-zone traffic.
B. Disable any protection profiles being applied to FTP traffic.
C. Create a new session helper for the FTP service monitoring port 2121.
D. Enable the ANY service in the firewall policies for both incoming and outgoing traffic.
正解:C
質問 2:
Which of the following statements are correct about the HA diag command diagnose sys ha reset-uptime? (Select all that apply.)
A. The device this command is executed on is likely to switch from master to slave status if master override is enabled.
B. The device this command is executed on is likely to switch from master to slave status if master override is disabled.
C. This command resets the uptime variable used in the HA algorithm so it may cause a new master to become elected.
D. This command has no impact on the HA algorithm.
正解:B,C
質問 3:
With FSSO, a domain user could authenticate either against the domain controller running the Collector Agent and Domain Controller Agent, or a domain controller running only the Domain Controller Agent.
If you attempt to authenticate with the Secondary Domain Controller running only the Domain Controller Agent, which of the following statements are correct? (Select all that apply.)
A. The FortiGate unit receives the user information from the Domain Controller Agent of the Secondary Controller.
B. The login event is sent to the Collector Agent.
C. The user cannot be authenticated with the FortiGate device in this manner because each Domain Controller Agent requires a dedicated Collector Agent.
D. The Collector Agent performs the DNS lookup for the authenticated client's IP address.
正解:B,D
質問 4:
A static route is configured for a FortiGate unit from the CLI using the following commands:
config router static edit 1 set device "wan1" set distance 20 set gateway 192.168.100.1 next end
Which of the following conditions is NOT required for this static default route to be displayed in the FortiGate unit's routing table?
A. You must disable DHCP client on that interface.
B. The Link Status of the wan1 interface is displayed as Up.
C. All other default routes should have an equal or higher distance.
D. The Administrative Status of the wan1 interface is displayed as Up.
正解:A
質問 5:
Which of the following statements are correct regarding Application Control?
A. Application Control is based on the AV engine.
B. Application Control cannot be applied to SSL encrypted traffic.
C. Application Control can be applied to SSL encrypted traffic.
D. Application Control is based on the IPS engine.
正解:C,D
質問 6:
Review the IPsec phase1 configuration in the Exhibit shown below; then answer the question following it.

Which of the following statements are correct regarding this configuration? (Select all that apply).
A. The local gateway IP is the address assigned to port1.
B. The phase1 is for a policy-based VPN configuration.
C. The phase1 is for a route-based VPN configuration.
D. The local gateway IP address is 10.200.3.1.
正解:A,C
質問 7:
What advantages are there in using a fully Meshed IPSec VPN configuration instead of a hub and spoke set of IPSec tunnels?
A. Using a full mesh topology provides stronger encryption.
B. Using a hub and spoke topology is required to achieve full redundancy.
C. Full mesh topology is the most fault-tolerant configuration.
D. Using a full mesh topology simplifies configuration.
正解:C
質問 8:
Which of the following cannot be used in conjunction with the endpoint compliance check?
A. HTTP Challenge Redirect to a Secure Channel (HTTPS) in the Authentication Settings.
B. Traffic shaping.
C. WAN optimization.
D. Any form of firewall policy authentication.
正解:A
質問 9:
An administrator is configuring a DLP rule for FTP traffic. When adding the rule to a DLP sensor, the administrator notes that the Ban Sender action is not available (greyed-out), as shown in the exhibit.

Which of the following is the best explanation for the Ban Sender action NOT being available?
A. The Ban Sender action is never available for FTP traffic.
B. The Ban Sender action needs to be enabled globally for FTP traffic on the FortiGate unit before configuring the sensor.
C. Firewall policy authentication is required before the Ban Sender action becomes available.
D. The Ban Sender action is only available for known domains. No domains have yet been added to the domain list.
正解:A
1184 お客様のコメント
クリック」





Kondo -
図解は教科書的な必要事項を記したものの他、挿絵のようなポップなものもあり書籍全体の物々しさを軽減しています。FCNSP.v5の問題集