Fortinet NSE5 Exam Practice Questions (P. 5)
- Full Access (313 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #41
Which of the following products is designed to manage multiple FortiGate devices?
- AFortiGate device
- BFortiAnalyzer device
- CFortiClient device
- DFortiManager device
- EFortiMail device
- FFortiBridge device
Correct Answer:
D
D
send
light_mode
delete
Question #42
Which of the following products provides dedicated hardware to analyze log data from multiple FortiGate devices?
- AFortiGate device
- BFortiAnalyzer device
- CFortiClient device
- DFortiManager device
- EFortiMail device
- FFortiBridge device
Correct Answer:
B
B
send
light_mode
delete
Question #43
Which of the following are valid FortiGate device interface methods for handling DNS requests? (Select all that apply.)
- AForward-only
- BNon-recursive
- CRecursive
- DIterative
- EConditional-forward
Correct Answer:
ABC
ABC
send
light_mode
delete
Question #44
The default administrator profile that is assigned to the default "admin" user on a FortGate device is:____________________.
send
light_mode
delete
Question #45
Which of the following logging options are supported on a FortiGate unit? (Select all that apply.)
send
light_mode
delete
Question #46
In order to match an identity-based policy, the FortiGate unit checks the IP information. Once inside the policy, the following logic is followed:
- AFirst, a check is performed to determine if the users login credentials are valid. Next, the user is checked to determine if they belong to any of the groups defined for that policy. Finally, user restrictions are determined and port, time, and UTM profiles are applied.
- BFirst, user restrictions are determined and port, time, and UTM profiles are applied. Next, a check is performed to determine if the users login credentials are valid. Finally, the user is checked to determine if they belong to any of the groups defined for that policy.
- CFirst, the user is checked to determine if they belong to any of the groups defined for that policy. Next, user restrictions are determined and port, time, and UTM
Correct Answer:
A
A
send
light_mode
delete
Question #47
Which of the following statements regarding the firewall policy authentication timeout is true?
- AThe authentication timeout is an idle timeout. This means that the FortiGate unit will consider a user to be "idle" if it does not see any packets coming from the users source IP.
- BThe authentication timeout is a hard timeout. This means that the FortiGate unit will remove the temporary policy for this users source IP after this timer has expired.
- CThe authentication timeout is an idle timeout. This means that the FortiGate unit will consider a user to be "idle" if it does not see any packets coming from the users source MAC.
- DThe authentication timeout is a hard timeout. This means that the FortiGate unit will remove the temporary policy for this user’s source MAC after this timer has
Correct Answer:
A
A
send
light_mode
delete
Question #48
Two-factor authentication is supported using the following methods? (Select all that apply.)
send
light_mode
delete
Question #49
Which of the following statements are true regarding Local User Authentication? (Select all that apply.)
- ALocal user authentication is based on usernames and passwords stored locally on the FortiGate unit.
- BTwo-factor authentication can be enabled on a per user basis.
- CAdministrators can create an account for the user locally and specify the remote server to verify the password.
- DLocal users are for administration accounts only and cannot be used for identity policies.
Correct Answer:
ABC
ABC
send
light_mode
delete
Question #50
Which of the statements below are true regarding firewall policy disclaimers? (Select all that apply.)
- AUser must accept the disclaimer to proceed with the authentication process.
- BThe disclaimer page is customizable.
- CThe disclaimer cannot be used in combination with user authentication.
- DThe disclaimer can only be applied to wireless interfaces.
Correct Answer:
AB
AB
send
light_mode
delete
All Pages