View the global IPS configuration, and then answer the question below.

Which of the following statements is true regarding this configuration?
A. IPS will scan every byte in every session.
B. New packets will be passed through without inspection if the IPS socket buffer runs out of memory.
C. IPS will use the faster matching algorithm which is only available for units with more than 4 GB memory.
D. FortiGate will spawn IPS engine instances based on the system load.
正解:A
質問 2:
View the exhibit, which contains the output of diagnose sys session stat, and then answer the question below.

Which statements are correct regarding the output shown? (Choose two.)
A. No sessions have been deleted because of memory pages exhaustion.
B. There are 0 ephemeral sessions.
C. All the sessions in the session table are TCP sessions.
D. There are 166 TCP sessions waiting to complete the three-way handshake.
正解:B,D
質問 3:
A FortiGate's portl is connected to a private network. Its port2 is connected to the Internet. Explicit web proxy is enabled in port1 and only explicit web proxy users can access the Internet. Web cache is NOT enabled. An internal web proxy user is downloading a file from the Internet via HTTP. Which statements are true regarding the two entries in the FortiGate session table related with this traffic? (Choose two.)
A. One session has the proxy flag on, the other one does not.
B. Both session have the local flag on.
C. One of the sessions has the IP address of port2 as the source IP address.
D. The destination IP addresses of both sessions are IP addresses assigned to FortiGate's interfaces.
正解:B,C
質問 4:
View the exhibit, which contains the output of a diagnose command, and then answer the question below.

Which statements are true regarding the output in the exhibit? (Choose two.)
A. FortiGate used 209.222.147.3 as the initial server to validate its contract.
B. Servers with the D flag are considered to be down.
C. Servers with a negative TZ value are experiencing a service outage.
D. FortiGate will probe 121.111.236.179 every fifteen minutes for a response.
正解:A,C
質問 5:
View the exhibit, which contains a screenshot of some phase-1 settings, and then answer the question below.

The VPN is up, and DPD packets are being exchanged between both IPsec gateways; however, traffic cannot pass through the tunnel. To diagnose, the administrator enters these CLI commands:

However, the IKE real time debug does not show any output. Why?
A. The log-filter setting was set incorrectly. The VPN's traffic does not match this filter.
B. The debug output shows phases 1 and 2 negotiations only. Once the tunnel is up, it does not show any more output.
C. The debug output shows phase 1 negotiation only. After that, the administrator must enable the following real time debug: diagnose debug application ipsec -1.
D. The debug shows only error messages. If there is no output, then the tunnel is operating normally.
正解:C
質問 6:
What does the dirty flag mean in a FortiGate session?
A. The next packet must be re-evaluated against the firewall policies.
B. Traffic has been identified as from an application that is not allowed.
C. Traffic has been blocked by the antivirus inspection.
D. The session must be removed from the former primary unit after an HA failover.
正解:A
クリック」


0 お客様のコメント