Fortinet NSE8 Exam Practice Questions (P. 1)
- Full Access (65 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
The dashboard widget indicates that FortiGuard Web Filtering is not reachable. However, AntiVirus, IPS, and Application Control have no problems as shown in the exhibit.

You contacted Fortinets customer service and discovered that your FortiGuard Web Filtering contract is still valid for several months.
What are two reasons for this problem? (Choose two.)

You contacted Fortinets customer service and discovered that your FortiGuard Web Filtering contract is still valid for several months.
What are two reasons for this problem? (Choose two.)
- AYou have another security device in front of FortiGate blocking ports 8888 and 53.
- BFortiGuard Web Filtering is not enabled in any firewall policy.
- CYou did not enable Web Filtering cache under Web Filtering and E-mail Filtering Options.
- DYou have a firewall policy blocking ports 8888 and 53.
Correct Answer:
AB
If Web filtering shows unreachable then we have to verify, whether web filtering enabled in security policies or not.
Web filtering enabled in a policy but the port 8888 and 53 are not selected, means the policy blocking the ports.
Reference:
http://cookbook.fortinet.com/troubleshooting-web-filtering/
AB
If Web filtering shows unreachable then we have to verify, whether web filtering enabled in security policies or not.
Web filtering enabled in a policy but the port 8888 and 53 are not selected, means the policy blocking the ports.
Reference:
http://cookbook.fortinet.com/troubleshooting-web-filtering/
send
light_mode
delete
Question #2
A customer is authenticating users using a FortiGate and an external LDAP server. The LDAP user, John Smith, cannot authenticate. The administrator runs the debug command diagnose debug application fnbamd 255 while John Smith attempts the authentication:
Based on the output shown in the exhibit, what is causing the problem?

Based on the output shown in the exhibit, what is causing the problem?

- AThe LDAP administrator password in the FortiGate configuration is incorrect.
- BThe user, John Smith, does have an account in the LDAP server.
- CThe user, John Smith, does not belong to any allowed user group.
- DThe user, John Smith, is using an incorrect password.Most Voted
Correct Answer:
A
Fortigate not binded with LDAP server because of failed authentication.
Reference:
http://kb.fortinet.com/kb/documentLink.do?externalID=FD31886
A
Fortigate not binded with LDAP server because of failed authentication.
Reference:
http://kb.fortinet.com/kb/documentLink.do?externalID=FD31886
send
light_mode
delete
Question #3

The exhibit shows an explicit Web proxy configuration in a FortiGate device. The FortiGate is installed between a client with the IP address 172.16.10.4 and a
Web server using port 80 with the IP address 10.10.3.4. The client Web browser is properly sending HTTP traffic to the FortiGate Web proxy IP address
172.16.10.254.
Which two sniffer commands will capture this HTTP traffic? (Choose two.)
- Adiagnose sniffer packet any ‘host 172.16.10.4 and host 172.16.10.254’ 3Most Voted
- Bdiagnose sniffer packet any ‘host 172.16.10.254 and host 10.10.3.4’ 3
- Cdiagnose sniffer packet any ‘host 172.16.10.4 and port 8080’ 3Most Voted
- Ddiagnose sniffer packet any ‘host 172.16.10.4 and host 10.10.3.4’ 3
Correct Answer:
CD
Sniffer should run between webproxy to webserver
And also Sniffer between client machine to web proxy connectivity as it is in explicit mode.
Reference:
http://www.maxnetwork.org/fortigate-packet-capture
CD
Sniffer should run between webproxy to webserver
And also Sniffer between client machine to web proxy connectivity as it is in explicit mode.
Reference:
http://www.maxnetwork.org/fortigate-packet-capture
send
light_mode
delete
Question #4
Your colleague has enabled virtual clustering to load balance traffic between the cluster units. You notice that all traffic is currently directed to a single FortiGate unit. Your colleague has applied the configuration shown in the exhibit.

Which step would you perform to load balance traffic within the virtual cluster?

Which step would you perform to load balance traffic within the virtual cluster?
- AIssue the diagnose sys ha reset-uptime command on the unit that is currently processing traffic to enable load balancing.
- BAdd an additional virtual cluster high-availability link to enable cluster load balancing.
- CInput Virtual Cluster domain 1 and Virtual Cluster domain 2 device priorities for each cluster unit.Most Voted
- DUse the set override enable command on both units to allow the secondary unit to load balance traffic.
Correct Answer:
C
Reference:
http://docs.fortinet.com/uploaded/files/1088/fortigate-ha-50.pdf
C
Reference:
http://docs.fortinet.com/uploaded/files/1088/fortigate-ha-50.pdf
send
light_mode
delete
Question #5
A data center for example.com hosts several separate Web applications. Users authenticate with all of them by providing their Active Directory (AD) login credentials. You do not have access to Example, Inc.s AD server. Your solution must do the following:
- provide single sign-on (SSO) for all protected Web applications
- prevent login brute forcing
- scan FTPS connections to the Web servers for exploits
- scan Webmail for OWASP Top 10 vulnerabilities such as session cookie hijacking, XSS, and SQL injection attacks
Which solution meets these requirements?
- provide single sign-on (SSO) for all protected Web applications
- prevent login brute forcing
- scan FTPS connections to the Web servers for exploits
- scan Webmail for OWASP Top 10 vulnerabilities such as session cookie hijacking, XSS, and SQL injection attacks
Which solution meets these requirements?
- AApply FortiGate deep inspection to FTPS. It must forward FTPS, HTTP, and HTTPS to FortiWeb. Configure FortiWeb to query the AD server, and apply SSO for Web requests. FortiWeb must forward FTPS directly to the Web servers without inspection, but proxy HTTP/HTTPS and block Web attacks.Most Voted
- BDeploy FortiDDos to block brute force attacks. Configure FortiGate to forward only FTPS, HTTP, and HTTPS to FortiWeb. Configure FortiWeb to query the AD server, and apply SSO for Web requests. Also configure it to scan FTPS and Web traffic, then forward allowed traffic to the Web servers.
- CUse FortiGate to authenticate and proxy HTTP/HTTPS; to verify credentials, FortiGate queries the AD server. Also configure FortiGate to scan FTPS before forwarding, and to mitigate SYN floods. Configure FortiWeb to block Web attacks.
- DInstall FSSO Agent on servers. Configure FortiGate to inspect FTPS. FortiGate will forward FTPS, HTTP, and HTTPS to FortiWeb. FortiWeb must block Web
Correct Answer:
D
FSSO agent integrate fortigate with AD then inspect bruteforce,FTPS,HTTP, and HTTPS using fortiweb and then forward all traffic to web server.
Reference:
http://cookbook.fortinet.com/providing-single-sign-using-ldap-fsso-agent-advanced-mode-expert/
D
FSSO agent integrate fortigate with AD then inspect bruteforce,FTPS,HTTP, and HTTPS using fortiweb and then forward all traffic to web server.
Reference:
http://cookbook.fortinet.com/providing-single-sign-using-ldap-fsso-agent-advanced-mode-expert/
send
light_mode
delete
All Pages