Refer to the exhibit, which shows a Branch1 configuration and routing table.
In the SD-WAN implicit rule, you do not want the traffic load balance for the overlay interface when all members are available.
In this scenario, which configuration change will meet this requirement?
A. Configure the priority in each overlay member to 10.
B. Change the load-balance-mode to source-ip-based.
C. Configure the cost in each overlay member to 10.
D. Create a new static route with the internet sdwan-zone only
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Refer to the exhibit showing an SD-WAN configuration.
According to the exhibit, if an internal user pings 10.1.100.2 and 10.1.100.22 from subnet 172.16.205.0/24, which outgoing interfaces will be used?
A. port1 and port15
B. port1 and port1
C. port16 and port1
D. port16 and port15
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Refer to the exhibits.
Exhibit A
Exhibit B
Exhibit C
A customer is trying to set up a VPN with a FortiGate, but they do not have a backup of the configuration. Output during a troubleshooting session is shown in the exhibits A and B and a baseline VPN configuration is shown in Exhibit C Referring to the exhibits, which configuration will restore VPN connectivity?
A.
B.
C.
D.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Refer to the exhibit.
FortiManager is configured with the Jinja Script under CLI Templates shown in the exhibit.
Which two statements correctly describe the expected behavior when running this template? (Choose two.)
A. The template will work if you change the variable format to {{ WAN }}.
B. The administrator must first manually map the interface for each device with a meta field.
C. The template will work if you change the variable format to $(WAN).
D. The Jinja template will automatically map the interface with "WAN" role on the managed FortiGate.
E. The template will fail because this configuration can only be applied with a CLI or TCL script.
F. The template will fail because this configuration can only be applied with a CLI or TCL script.
正解:B,E
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Refer to the exhibits.
The exhibits show a FortiMail network topology, Inbound configuration settings, and a Dictionary Profile.
You are required to integrate a third-party's host service (srv.thirdparty.com) into the e-mail processing path.
All inbound e-mails must be processed by FortiMail antispam and antivirus with FortiSandbox integration. If the email is clean, FortiMail must forward it to the third-party service, which will send the email back to FortiMail for final delivery, FortiMail must not scan the e-mail again.
Which three configuration tasks must be performed to meet these requirements? (Choose three.)
A. Change the scan order in FML-GW to antispam-sandbox-content.
B. Apply the Catch-AII profile to the ASinbound profile and configure an access delivery rule to deliver to the 100.64.0.72 host.
C. Create an IP policy with a Source value of 100. 64 .0.72/32, enable precedence, and place the policy at the top of the list.
D. Create an access receive rule with a Sender value of srv. thirdparcy.com, Recipient value of *@acme.com, and action value of Safe
E. Apply the Catch-Ail profile to the CFInbound profile and configure a content action profile to deliver to the srv. thirdparty. com FQDN
正解:A,C,E
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Refer to the exhibit.
A customer has deployed a FortiGate 300E with virtual domains (VDOMs) enabled in the multi-VDOM mode. There are three VDOMs: Root is for management and internet access, while VDOM 1 and VDOM 2 are used for segregating internal traffic. AccountVInk and SalesVInk are standard VDOM links in Ethernet mode.
Given the exhibit, which two statements below about VDOM behavior are correct? (Choose two.)
A. Traffic on AccountVInk and SalesVInk will not be accelerated.
B. Root VDOM is an Admin type VDOM, while VDOM 1 and VDOM 2 are Traffic type VDOMs.
C. You can apply OSPF routing on the VDOM link in either PPP or Ethernet mode
D. The VDOM links are in Ethernet mode because they have IP addressed assigned on both sides.
E. OSPF routing can be configured between VDOM 1 and Root VDOM without any configuration changes to AccountVInk
正解:B,C
解説: (Pass4Test メンバーにのみ表示されます)
Kawaguchi -
ネットから調べさせて、Pass4Testという素晴らしいサイトに出会いました。とても素晴らしい内容となっております。