Exhibit
Click the Exhibit button. Referring to the exhibit, which two behaviors will the FortiClient endpoint have after receiving the profile update from the FortiClient EMS? (Choose two.)

A. The user will not be able to access a Web downloaded file when the FortiSandbox is unreachable.
B. The user will not be able to access a Web downloaded file for a maximum of 60 seconds if it is not a virus and the FortiSandbox s reachable.
C. The user will not be able to access a Web downloaded file for at least 60 seconds when the FortiSandbox is reachable.
D. Files executed from a mapped network drive will not be inspected by the FortiCltent endpoint Antivirus engine.
正解:A,B
質問 2:
You are asked to add a FortiDDoS to the network to combat detected slow connection attacks such as Slowloris.
Which prevention mode on FortiDDoS will protect you against this specific type of attack?
A. rate limiting mode
B. asymmetric mode
C. aggressive aging mode
D. blocking mode
正解:C
質問 3:
You deploy a FortiGate device in a remote office based on the requirements shown below.
-- Due to company's security policy, management IP of your FortiGate is not allowed to access the Internet.
-- Apply Web Filtering, Antivirus, IPS and Application control to the protected subnet.
-- Be managed by a central FortiManager in the head office.
Which action will help to achieve the requirements?
A. Configure the FortiGuard override server and use the IP address of the FortiManager
B. Configure the FortiGuard override server and use the IP address of service, fortiguard net.
C. Configure a default route and make sure that the FortiGate device can pmg to service fortiguard net.
D. Configure FortiGate to use FortiGuard Filtering Port 8888.
正解:A
質問 4:
Click the Exhibit button.

Referring to the exhibit, which two statements are true? (Choose two.)
A. LAG-3 on switches on FS448D-A and FS448D-B may be connected to a single 802 3ad trunk on another device.
B. port13 and port14 on FS448D-A should be connected to port13 and port14 on FS448D-B.
C. LAG-1 and LAG 2 should be connected to a single 4-port 802 3ad interface on the FortiGate-A.
D. LAG-1 and LAG-2 should be connected to a 4-port single 802 3ad trunk on another device.
正解:A,B
質問 5:
In a FortiGate 5000 series, two FortiControllers are working as an SLBC cluster in a-p mode. The configuration shown below is applied.
config load-balance session-setup
set tcp-ingress enable
end
When statement is true on how new TCP sessions are handled by the Distributor Processor (DP).
A. No new session is added is the DP session table until the processing worker accepts the traffic.
B. A new session added in the OP session table remains is the table only if traffic is traffic is accepted by the processing worker.
C. A new session added m the DP session table remains in the table remain in the traffic is denied by the procession worker.
D. The new session added the DP session table is automatically deleted, if the traffic is denied by the processing worker.
正解:C
質問 6:
You configure an outgoing firewall policy with a web filter for accessing the internet. The access to URL
https// itacm.co and web belonging to the same category should be blocked. You notice that the Web server presents a certificate with CN=www acme.com. The www.it.acme site is as '' information Technology and the www.acme.com site is categorized as ''Business".
Which statements is correct in this scenario?
A. SSL inspection must be configured to deep-inspection: the category "information Technology "needs to be blocked.
B. Category :information Technology" needs to be blocked, the SNI takes precedence over the certificate name.
C. Category "Business" need a to be block: the certificate name takes precedence over the SNI.
D. Category "information Technology" needs to blocked, the FortiGate is able to inspection the URL with HTTPS sessions.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)



0 お客様のコメント