Fortinet NSE8_810 Exam Practice Questions (P. 3)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
You want to manage a FortiGate with the FortiCloud service.
The FortiGate shows up in your list of devices on the FortiGate Web Site, but all management functions are either missing or grayed out. Which statement is correct in this scenario?
The FortiGate shows up in your list of devices on the FortiGate Web Site, but all management functions are either missing or grayed out. Which statement is correct in this scenario?
- AThe managed FortiGate is running a version of FortiOS that is either too new or too old for FortiCloud.
- BThe managed FortiGate requires that a FortiCloud management license be purchased and applied. configure system central-management on the FortiGate CLI and set the management type to fortiguard.
- CYou must manually normal.
- DThe management tunnel mode on the managed FortiGate must be changed to
Correct Answer:
C
C
send
light_mode
delete
Question #12
FortiMail is configured with the protected domain "internal.lab".
Which two envelope addresses will need an access control rule to relay e-mail sent for unauthenticated users? (Choose two.)
Which two envelope addresses will need an access control rule to relay e-mail sent for unauthenticated users? (Choose two.)
- AMAIL FROM: [email protected];RCPT TO;[email protected]
- BMAIL FROM: [email protected];RCPT TO;[email protected]
- CMAIL FROM: [email protected];RCPT TO;[email protected]
- DMAIL FROM: student@ internal.lab;RCPT TO;[email protected]
Correct Answer:
BC
BC
send
light_mode
delete
Question #13
You deploy a FortiGate device in a remote office based on the requirements shown below.
-Due to company's security policy, management IP of your FortiGate is not allowed to access the Internet.
- Apply Web Filtering, AntiVirus, IPS and Application control to the protected subnet.
- Be managed by a central FortiManager on the head office.
Which action will help to achieve the requirements?
-Due to company's security policy, management IP of your FortiGate is not allowed to access the Internet.
- Apply Web Filtering, AntiVirus, IPS and Application control to the protected subnet.
- Be managed by a central FortiManager on the head office.
Which action will help to achieve the requirements?
- AConfigure a default route and make sure that the FortiGate device can ping to service.fortiguard.net
- BConfigure the FortiGuard override server and use the IP address of the FortiManager.
- CConfigure the FortiGuard override server and use the IP address of service.fortiguard.net.
- DConfigure FortiGuard to use FortiGuard Filtering Port 8888.
Correct Answer:
B
B
send
light_mode
delete
Question #14
Click the Exhibit button.

You log into FortiManager, look at the Device Manager window and notice that one of your managed devices is not in normal status.
Referring to the exhibit, which two statements correctly describe the affected device's status and result? (Choose two.)

You log into FortiManager, look at the Device Manager window and notice that one of your managed devices is not in normal status.
Referring to the exhibit, which two statements correctly describe the affected device's status and result? (Choose two.)
- AThe device configuration was changed on the local FortiGate side only; auto-update is disabled.
- BThe device configuration was changed on both the local FortiGate side and the FortiManager side; auto-update is disabled.
- CThe changed configuration on the FortiGate will remain the next time that the device configuration is pushed form FortiManager.
- DThe changed configuration on the FortiGate will be overwritten in favor of what is on the FortiManager the next time that the device configuration is pushed.
Correct Answer:
BD
BD
send
light_mode
delete
Question #15
A FortiOS device is used for termination of VPNs for a number of remote spoke VPN units (designated Group A spokes) using a phase 1 main mode dial-up tunnel using pre-shared keys. Your company recently acquired another organization. You are asked to establish VPN connectivity for the newly acquired organization's sites for which new devices will be provisioned (designated Group B spokes). Both existing (Group A) and new (Group B) spoke units are dynamically addressed. You are asked to ensure that spokes from the acquired organization (Group B) have different access permissions that your existing VPN spokes units (Group A).
Which two solutions meet the requirements for the new spoke group? (Choose two.)
Which two solutions meet the requirements for the new spoke group? (Choose two.)
- AImplement a new phase 1 dial-up main mode tunnel with preshared keys and XAuth. Use identity policies to filter traffic.
- BImplement a new phase 1 dial-up main mode tunnel with a different pre-shared key than Group A spokes. Use standard policies to filter traffic for the new dial- up tunnel.
- CImplement a new phase 1 dial-up main mode tunnel with certificate authentication. Use standard policies to filter traffic for the new dial-up tunnel.
- DImplement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID. Use standard policies to filter traffic for the new dial-up tunnel.
Correct Answer:
AB
AB
send
light_mode
delete
All Pages