Fortinet NSE8 Exam Practice Questions (P. 4)
- Full Access (65 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
An administrator wants to assign static IP addresses to users connecting tunnel-mode SSL VPN. Each SSL VPN user must always get the same unique IP address which is never assigned to any other user.
Which solution accomplishes this task?
Which solution accomplishes this task?
- ATACACS+ authentication with an attribute-value (AV) pair containing each user’s IP address.
- BRADIUS authentication with each user’s IP address stored in a Vendor Specific Attribute (VSA).Most Voted
- CLDAP authentication with an LDAP attribute containing each user’s IP address.
- DFSSO authentication with an LDAP attribute containing each user’s IP address.
Correct Answer:
D
D
send
light_mode
delete
Question #17

The exhibit shows an LDAP server configuration in a FortiGate device. The LDAP user, John Smith, has the following LDAP attributes:

John Smiths LDAP password is ABC123.
Which CLI command should you use to test the LDAP authentication using John Smiths credentials?
- Adiagnose test authserver ldap Lab jsmith ABC123
- Bdiagnose test authserver ldap-direct Lab jsmith ABC123
- Cdiagnose test authserver ldap Lab ‘John Smith’ ABC123
- Ddiagnose test authserver ldap-direct Lab john ABC123
Correct Answer:
A
https://forum.fortinet.com/tm.aspx?m=119178
A
https://forum.fortinet.com/tm.aspx?m=119178
send
light_mode
delete
Question #18
Your NOC contracts the security team due to a problem with a new application flow. You are instructed to disable hardware acceleration for the policy shown in the exhibit for troubleshooting purposes.

Which command will disable hardware acceleration for the new application policy?
A)

B)

C)

D)


Which command will disable hardware acceleration for the new application policy?
A)

B)

C)

D)

- AOption A
- BOption B
- COption C
- DOption D
Correct Answer:
D
http://docs.fortinet.com/uploaded/files/1607/fortigate-hardware-accel-50.pdf
D
http://docs.fortinet.com/uploaded/files/1607/fortigate-hardware-accel-50.pdf
send
light_mode
delete
Question #19
Your company uses a cluster of two FortiGate 3600C units in active-passive mode to protect the corporate network. The FortiGate cluster sends its logs to a
FortiAnalyzer and you have configured scheduled weekly reports for the Internet bandwidth usage of each corporate VLAN. During a scheduled maintenance window, you make a series of configuration changes. When the next FortiAnalyzer weekly report is generated, you notice that Internet bandwidth usage reported by the FortiAnalyzer is far less than expected.
What is the reason for this discrepancy?
FortiAnalyzer and you have configured scheduled weekly reports for the Internet bandwidth usage of each corporate VLAN. During a scheduled maintenance window, you make a series of configuration changes. When the next FortiAnalyzer weekly report is generated, you notice that Internet bandwidth usage reported by the FortiAnalyzer is far less than expected.
What is the reason for this discrepancy?
- AYou applied an antivirus profile on some of the policies, and no traffic can be accelerated.
- BYou disabled all security profiles on some of the firewall policies, and the traffic matching those policies is now accelerated.
- CYou enabled HA session-pickup, which is turn disabled session accounting.
- DYou changed from active-passive to active-active, causing the session traffic counters to become inaccurate.
Correct Answer:
D
Because of Active/Active failover traffic segregate to boxes where it reduces the bandwidth utilization
D
Because of Active/Active failover traffic segregate to boxes where it reduces the bandwidth utilization
send
light_mode
delete
Question #20
You notice that memory usage is high and FortiGate has entered conserve mode. You want FortiGates IPS engine to focus only on exploits and attacks that are applicable to your specific network.
Which two steps would you take to reduce RAM usage without weakening security? (Choose two.)
Which two steps would you take to reduce RAM usage without weakening security? (Choose two.)
- AConfigure IPS to pass files that are larger than a specific threshold, instead of buffering and scanning them.
- BReduce the size of the signature three (filters) that FortiGate must search by disabling scans for applications and OS stacks that do not exist on your network.Most Voted
- CDisable application control for protocols that are not used on your network.Most Voted
- DDisable IPS for traffic destined for the FortiGate itself.
Correct Answer:
AD
AD
send
light_mode
delete
All Pages