Fortinet NSE8 Exam Practice Questions (P. 5)
- Full Access (65 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
A caf offers free Wi-Fi. Customers portable electronic devices often do not have antivirus software installed and may be hosting worms without their knowledge.
You must protect all customers from any other customers infected devices that join the same SSID.
Which step meets the requirement?
You must protect all customers from any other customers infected devices that join the same SSID.
Which step meets the requirement?
- AEnable deep SSH inspection with antivirus and IPS.
- BUse a captive portal to redirect unsecured connections such as HTTP and SMTP to their secured equivalents, preventing worms on infected clients from tampering with other customer traffic.
- CUse WPA2 encryption and configure a policy on FortiGate to block all traffic between clients.
- DUse WPA2 encryption, and enable "Block Intra-SSID Traffic".
Correct Answer:
D
D
send
light_mode
delete
Question #22
You verified that application control is working from previous configured categories. You just added Skype on blocked signatures. However, after applying the profile to your firewall policy, clients running Skype can still connect and use the application.
What are two causes of this problem? (Choose two.)
What are two causes of this problem? (Choose two.)
- AThe application control database is not updated.
- BSSL inspection is not enabled.
- CA client on the network was already connected to the Skype network and serves as relay prior to configuration changes to block Skype
- DThe FakeSkype.botnet signature is included on your application control sensor.
Correct Answer:
AB
AB
send
light_mode
delete
Question #23
Given the following FortiOS 5.2 commands:

Which vulnerability is being addresses when managing FortiGate through an encrypted management protocol?

Which vulnerability is being addresses when managing FortiGate through an encrypted management protocol?
- ARemote Exploit Vulnerability in Bash (ShellShock)
- BInformation Disclosure Vulnerability in OpenSSL (Heartbleed)
- CSSL v3 POODLE Vulnerability
- DSSL/TLS MITM vulnerability (CVE-2014-0224)
Correct Answer:
C
http://kb.fortinet.com/kb/documentLink.do?externalID=FD36913
C
http://kb.fortinet.com/kb/documentLink.do?externalID=FD36913
send
light_mode
delete
Question #24

Given the following error message:

FortiManager fails to import policy ID 1.
What is the problem?
- AFortiManager already has Address LAN which has interface mapping set to "internal" in its database, it is contradicting with the STUDENT-2 FortiGate device which has address LAN mapped to "any".
- BFortiManager already has address LAN which has interface mapping set to "any" in its database; this conflicts with the STUDENT-2 FortiGate device which has address "LAN" mapped to "internal".
- CPolicy ID 1 for this managed FortiGate device already exists on the FortiManager policy package named STUDENT-2.
- DPolicy ID 1 does not have interface mapping on FortiManager.
Correct Answer:
D
http://kb.fortinet.com/kb/documentLink.do?externalID=FD38544
D
http://kb.fortinet.com/kb/documentLink.do?externalID=FD38544
send
light_mode
delete
Question #25
You are an administrator of FortiGate devices that use FortiManager for central management. You need to add a policy on an ADOM, but upon selecting the
ADOM drop-down list, you notice that the ADOM is in locked state. Workflow mode is enabled on your FortiManager to define approval or notification workflow when creating and installing policy changes.
What caused this problem?
ADOM drop-down list, you notice that the ADOM is in locked state. Workflow mode is enabled on your FortiManager to define approval or notification workflow when creating and installing policy changes.
What caused this problem?
- AAnother administrator has locked the ADOM and is currently working on it.
- BThere is pending approval waiting from a previous modification.
- CYou need to use set workspace-mode workflow on the CLI.
- DYou have read-only permission on Workflow Approve in the administrator profile.
Correct Answer:
D
http://docs.fortinet.com/uploaded/files/2250/FortiManager-5.2.1-Administration-Guide.pdf
D
http://docs.fortinet.com/uploaded/files/2250/FortiManager-5.2.1-Administration-Guide.pdf
send
light_mode
delete
All Pages