Fortinet NSE8_812 Exam Practice Questions (P. 3)
- Full Access (117 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #11
Refer to the exhibit.

You are operation an internal network with multiple OSPF routers on the same LAN segment. FGT_3 needs to be added to the OSPF network and has the configuration shown in the exhibit. FGT_3 is not establishing any OSPF connection.
What needs to be changed to the configuration to make sure FGT_3 will establish OSPF neighbors without affecting the DR/BDR election?

You are operation an internal network with multiple OSPF routers on the same LAN segment. FGT_3 needs to be added to the OSPF network and has the configuration shown in the exhibit. FGT_3 is not establishing any OSPF connection.
What needs to be changed to the configuration to make sure FGT_3 will establish OSPF neighbors without affecting the DR/BDR election?
send
light_mode
delete
Question #12
A retail customer with a FortiADC HA cluster load balancing five webservers in L7 Full NAT mode is receiving reports of users not able to access their website during a sale event. But for clients that were able to connect, the website works fine.
CPU usage on the FortiADC and the web servers is low, application and database servers are still able to handle more traffic, and the bandwidth utilization is under 30%.
Which two options can resolve this situation? (Choose two.)
CPU usage on the FortiADC and the web servers is low, application and database servers are still able to handle more traffic, and the bandwidth utilization is under 30%.
Which two options can resolve this situation? (Choose two.)
- AChange the persistence rule to LB_PERSIS_SSL_SESS_ID
- BAdd more web servers to the real server pool
- CDisable SSL between the FortiADC and the web servers
- DAdd a connection-pool to the FortiADC virtual server
Correct Answer:
A
A
send
light_mode
delete
Question #13
Refer to the CLI output:

Given the information shown in the output, which two statements are correct? (Choose two.)

Given the information shown in the output, which two statements are correct? (Choose two.)
- AGeographical IP policies are enabled and evaluated after local techniques
- BAttackers can be blocked before they target the servers behind the FortiWebMost Voted
- CThe IP Reputation feature has been manually updated
- DAn IP address that was previously used by an attacker will always be blocked
- EReputation from blacklisted IP addresses from DHCP or PPPoE pools can be restoredMost Voted
Correct Answer:
BE
BE
send
light_mode
delete
Question #14
Refer to the exhibit.

You are deploying a FortiGate 6000F. The device should be directly connected to a switch. In the future, a new hardware module providing higher speed will be installed in the switch, and the connection to the FortiGate must be moved to this higher-speed port.
You must ensure that the initial FortiGate interface connected to the switch does not affect any other port when the new module is installed and the new port speed is defined.
How should the initial connection be made?

You are deploying a FortiGate 6000F. The device should be directly connected to a switch. In the future, a new hardware module providing higher speed will be installed in the switch, and the connection to the FortiGate must be moved to this higher-speed port.
You must ensure that the initial FortiGate interface connected to the switch does not affect any other port when the new module is installed and the new port speed is defined.
How should the initial connection be made?
- AConnect the switch on any interface between ports 21 to 24
- BConnect the switch on any interface between ports 25 to 28Most Voted
- CConnect the switch on any interface between ports 1 to 4
- DConnect the switch on any interface between ports 5 to 8
Correct Answer:
A
A
send
light_mode
delete
Question #15
You are designing a setup where the FortiGate device is connected to two upstream ISPs using BGP. Part of the requirement is that you must be able to refresh the route advertisements manually without disconnecting the BGP neighborships.
Which feature must you enable on the BGP neighbors to accomplish this goal?
Which feature must you enable on the BGP neighbors to accomplish this goal?
- AGraceful-restart
- BDeterministic-med
- CSynchronization
- DSoft-reconfigurationMost Voted
Correct Answer:
D
D
send
light_mode
delete
All Pages