option
Questions
ayuda
daypo
search.php

saboneteverdeoliva

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
saboneteverdeoliva

Description:
Sabonetedeolivaasdfa Asd

Creation Date: 2026/09/16

Category: Others

Number of questions: 20

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

Refer to the exhibit. Partial output of a real-time OSPF debug is shown. Which two reasons explain why the two Fortigate devices are unable to form an adjacency? (Choose Two answers). A. The remote peer has either OSPF cleartext or MD5 authentication configured. B. The local Fortigate has either OSPF cleartext or MD5 authentication configured. C. There is an OSPF authentication configuration mismatch. D. The local Fortigate does not have OSPF authentication configured.

Refer to the exhibits. The system administrator settings configured on a root Fortigate and the Security Fabric settings configured on a downstream Fortigate are shown. When prompted to sign in with Security Fabric to the downstream Fortigate, a user enters the single sign-on (SSO) provider credentials. Whats is the resulti? (Choose one answer). A. The user is prompted to create an administrator account for AdminSSO. B. The downstream Fortigate creates an SSO administrator account for AdminSSO with the super_admin readonly profile. C. The downstream Fortigate creates an SSO administrator account for AdminSSO with the super_admin profile. D. The downstream Fortigate relies on the root Fortigate and does not create an administrator account.

You want to configure two static routes. One that references a zone and the second one that references an SD-WAN member that belongs to that zone. Which statemente about this scenario is true? (Choose one answer). A. You cannot create static routes for individual SD-WAN members. B. You cannot create static routes that reference an SD-WAN zone. C. The destination subnets must be different. D. The source subnets must be different.

Refer to the exhibit. Based on the exhibit, what is the first message that Spoke 1 replies to the hub instructiong it to bring up the dynamic tunnel if a client generates traffic destined to Spoke 2? (Choose one answer). A. Shortcut query. B. Shortcut reply. C. Shortcut offer. D. Shortcut forward.

Refer to the exhibit. The output of the diagnose sys session list command is shown If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary? (Choose one answer). A. The session state is preserved, but the kernel will re-evaluate the session because the routing information will be flushed. B. The session continues to permit traffic on the new primary device after failiver, without requiring the client to restart the session with the server. C. The session is synchronized with the secondary device; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover. D. The session will be removed from the session table of the secondary device because the TCP session is not yet fully established.

Refer to the exhibit. The packet capture output of a client hello message is shown. You are updating a firewall policy that includes SSL certificate inspection, You are capturing packets from the traffic passing through this firewall policy. Which two statements about the packet capture are correct? (Choose two answers). A. You can effectively apply an antivirus security profile to this traffic. B. The subject alternative name (SAN) is necessary to apply security profiles. C. The client supports only TLS versions 1.2 and 1.3. D. You can effectively apply a web filtering profile to this traffic.

While troubleshooting a Fortigate web filter issue, users report that they cannot access any websites, even though those sites are not explicitly blocked by any web filter profiles that are applied to firewall policies. What are the threee most likely reasons for hist behavior? (Choose Three answers). A. The SSL/TLS deep inspection was configured but the browsers do not have the Fortigate certificate installed. B. The webfilter-force-off setting has been enabled under config system fortiguard. C. the web filter cache has been cleared causing all websites to take longer to be rated. D. The DNS server is unreachable, preventing URL resolution. E. The Fortiguard Web Filtering license has expired, causing Fortigate to apply the default block action.

Refer to the exhibit. A network topology and the routing table of a Fortigate device is shown. What must the administrator configure in the BGP section to add only the subnet 100.64.2.0/24 in the routing table of Fortigate_A? (Choose one answer). A. The administrator must configure route-map in on Fortigate_A. B. The administrator must configure connected routes redistribution on Fortigate_C. C. The administrator must configure the 100.64.2.0/24 network on Fortigate_C. D. The administrator must configure BGP route redistribuition on Fortigate_B.

If you configure set tcp-mss-sender and set tcp-mss-receiver in a firewall policy, how dows it affect the size and handling of TCP packets in the network? (Choose one answer). A. The commands affect the payload size of the packet and the size of the IP header for handling TCP packets. B. The TCP packet modifies the packet size only if no fragmentation occurs. C. Applying commands in a firewall policy determines the largest payload a device can handle in a single TCP segment. D. The maximum segment size permitted in the firewall policy determines whether TCP packets are alloweb or denied.

Refer to the exhibits. The SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration are shown. When you try to install the configuration changes, FortiManager displays an error message. How can you fix the issue? (Choose one answer). A. Configure HUB1 as the destination of policy 3. B. Configure both HUB1-VPN1 and HUB1-VPN2 as the destionation of policy 3. C. Configure branch1_fgt as the installation target for policy 3. D. Configure a normalized interface for the IPsec tunnel HUB1-VPN1.

Refer to the exhibit. The ADVPN IPsec interface represents the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub B to Spoke 3 and Spoke 4. You must configure an ADVPN using IBGP and EBGP to connect Overlay 1 with Overlay 2. Which parameters must you configure in the phase 1 VPN IPsec configuration of the ADVPN tunnels? (Choose one answer). A. set auto-discovery-sender enable and set network-id x. B. set auto-discovery-forwarder enable and set remote-as x. C.set auto-discovery-receiver enable and set remote-ip x. D. set auto-discovery-crossover enable and set enforce-multihop enable.

What are Three key routing preinciples of SD-WAN? (Choose three answers). A. Routes to directly connected subnets have precedence over SD-WAN rules. B. Internet Service Database (ISDB) routes have precedence over SD-WAN rules. C.SD-WAN rules are skipped if the best route to the destionation is a static route. D. SD-WAN members are skipped if they do not have a valid route to the destination. E. SD-WAN rules are skipped if the best route to the destionation is not an SD-WAN member.

You want to configure SD-WAN on a few Fortigate devices to optimize the use of WAN links and secure internet access. The devices are standalone Fortigate, already centrally managed by FortiManager. Which statement applies? (Choose one answer). A. You can keep the devices in the Device Manager section. You can configure per-device SD-WAN settings. B. You must move the devices to the SD-WAN Manager section and use the SD-WAN standalone wizard. C. You must move the devices to the SD-WAN Manager section before you can configure SD-WAN rules. D. You can keep the devices in the Device manager section, but you must place them in a dedicated device group.

You use the FortiManager SD-WAN overlay archstrator to prepare an SD-WAN deployment. Using information provided through the SD-WAN overlay template wizard, Fortimanager creates templates that are ready to install on the spoke and hub devices. Wich three templates are created by the SD-WAN overlay orchestrator for a spoke device? (Choose three answers). A. Rules template. B. CLI template. C. IPsec tunnel template. D. BGP template. E. Static route template.

Rfer to the exhibit. The VDOM configuration on a Fortigate device is shown. You discover that web filtering stopped working in Core1 and Core2 after a maintenance windows. What are two reasons why web filtering stopped working? (Choose two answers). A. The root VDOM does not have access to FortiManager in a closed network. B. The root VDOM does not have access to any valid, public Fortinet Distribution Network (FDN). C. The Core1 and Core2 VDOMs must also be enabled as management VDOMs to receive FortiGuard updates. D. The root VDOM does not use a VDOM link to connect with the Core1 and Core2 VDOMs.

Refer to the exhibit. For you ZTP deployment, you review the CSV file shown in the exhibit and note that it is missing important information. Which two elements must you change before you can import it into FortiManager? (Choose two answers). A. You must define a name for each device. B. You must associate a device blueprint with each device. C. You must define a value for each device and each user-defined metadata variable. D. You must define a value for each device and each metadata variable that defines an IP address.

In a transparent VDOM interface, what does the command set forward-domain <domain_ID> do? (Choose one answer). A. It isolates traffic within a specific VLAN by assingning a broadcast domain to an interface based on the VLAN ID. B. It allows the interface to access the configured admin domain. C. It assigns a unique domain ID to the interface, allowing it to operate across multiple VLANs within the same VDOM. D. It restricts the interface to managing traffic from only the specified VLAN, effectively segregating network traffic.

Refer to the exhibit. An SD-WAN zone configuration on the FortiGate GUI is shown. What can you conclude about the zone and member configuration on this device? (Choose one answer). A. You can delete the WAN1 zone. B. You can add the member B-125 to the WAN3 zone and keep it as a member of the Test zone. C. You can delete the virtual-wan-link-zone. D. The WAN2 zone contains no member.

Refer to the exhibits Which two statements are true about the health and performance of SD-WAN members 3 and 4? (Choose Two Answers). A. Encrypted traffic is not used for the performance measurement. B. The performance is an average of the metrics measured for Facebook and Youtube traffic passing through the member. C. Only related TCP traffic is used for performance measurement. D. Fortigate identifies the member as dead when there is no Facebook and Youtube traffic passing through the member.

In a Security Fabric environment, which three actions must you take to ensure sucessful communication among the nodes? (Choose threee answers). A. You must configure Fortigate in transparent mode. B. You must enable FortiTelemetry on the receiving interface of the upstream Fortigate. C. You must ensure that TCP port 8013 is not blocked along the way. D. You must ensure that the port for Neighbor Discovery has been changed. E. You must authorize the downstream Fotigate on the root Fortigate.

Report abuse