Fortinet NSE8_810 Exam Practice Questions (P. 2)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Click the Exhibit button.
You configured an IPsec tunnel to a branch office. Now you want to make sure that the encryption of the tunnel is offloaded to hardware.
Referring to the exhibit, which statement is true?

You configured an IPsec tunnel to a branch office. Now you want to make sure that the encryption of the tunnel is offloaded to hardware.
Referring to the exhibit, which statement is true?

- AIncoming and outgoing traffic is offloaded.
- BOutgoing traffic is offloaded; you cannot determine if incoming traffic is offloaded at this time.
- CTraffic is not offloaded.
- DOutgoing traffic is offloaded; incoming traffic not offloaded.
Correct Answer:
D
D
send
light_mode
delete
Question #7
You want to access the JSON API on FortiManager to retrieve information on an object.
In this scenario, which two methods will satisfy the requirement? (Choose two.)
In this scenario, which two methods will satisfy the requirement? (Choose two.)
- AMake a call with the Web browser on your workstation.
- BMake a call with the SoapUPI API tool on your workstation.
- CDownload the WSDL file from FortiManager administration GUI. curl utility on your workstation.
- DMake a call with the
Correct Answer:
CD
CD
send
light_mode
delete
Question #8
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device's Web GUI is accessed. You cannot seem to create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support.
You need to prevent the false positive IPS alerts from occuring.
In this scenario, which two actions would accomplish this task? (Choose two.)
You need to prevent the false positive IPS alerts from occuring.
In this scenario, which two actions would accomplish this task? (Choose two.)
- ACreate a very granular firewall policy for that device's IP address which does not perform IPS scanning.
- BReconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based. Exempt action for that device's IP address.
- CCreate a URL filter with the
- DChange the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.
Correct Answer:
AD
AD
send
light_mode
delete
Question #9
Click the Exhibit button.
A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.
However, FortiGates A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The IKE real time debug shows the output in the exhibit when site A is disconnected.
Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time?
set enforce-unique-id disable
A.
set add-route enable
B.
set single-source disable
C.
set route-overlap allow
D.
A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.
However, FortiGates A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The IKE real time debug shows the output in the exhibit when site A is disconnected.
Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time?

A.
set add-route enable
B.
set single-source disable
C.
set route-overlap allow
D.
send
light_mode
delete
Question #10
Click the Exhibit button. The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb. Which statement represents the purpose of this policy?


- AThe policy redirects all HTTP URLs to HTTPS.
- BThe policy redirects all HTTPS URLs to HTTP.
- CThe policy redirects only HTTPS URLs containing ^/(.*)$ string to HTTP.
- DThe policy redirects only HTTPS URLs containing ^/(.*)$ string to HTTPS.
Correct Answer:
A
A
send
light_mode
delete
All Pages