New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Fortinet NSE8_811 Dumps Questions Answers

Page: 1 / 2
Total 65 questions

Fortinet NSE 8 Written Exam (NSE8_811) Questions and Answers

Question 1

Click the Exhibit button.

Referring to the exhibit, which two statements are true about local authentication? (Choose two.)

Options:

A.

The FortiGate will allow the TCP connection when a ClientHello message indicating a renegotiation is

received.

B.

The user’s IP address will be blocked 15 seconds after five login failures.

C.

The user will be blocked 15 seconds after five login failures.

D.

The user will need to re-authenticate after five minutes.

Buy Now
Question 2

Refer to the exhibit.

You are working on FortiGate 61E operating in flow-based inspection mode with various settings optimized for performance. The main Internet firewall policy is using the "default" antivirus profile. You found that some executable virus samples files downloaded over HTTP are not being blocked by the FortiGate.

Referring to the exhibit, how can this be fixed?

Options:

A.

Change the set scan-mode configuration to full.

B.

Disable the emulator feature.

C.

Change the set default-db configuration to extreme.

D.

Add set content-disarm enable to the configuration.

Question 3

You deploy a FortiGate device in a remote office based on the requirements shown below.

-- Due to company's security policy, management IP of your FortiGate is not allowed to access the Internet.

-- Apply Web Filtering, Antivirus, IPS and Application control to the protected subnet.

-- Be managed by a central FortiManager in the head office.

Which action will help to achieve the requirements?

Options:

A.

Configure a default route and make sure that the FortiGate device can pmg to service fortiguard net.

B.

Configure the FortiGuard override server and use the IP address of the FortiManager

C.

Configure the FortiGuard override server and use the IP address of service, fortiguard net.

D.

Configure FortiGate to use FortiGuard Filtering Port 8888.

Question 4

A company has just deployed a new FortiMail in gateway mode. The administrator is asked to strengthen e-mail protection by applying the policies shown below.

- E-mails can only be accepted if a valid e-mail account exists.

- Only authenticated users can send e-mails out

Which two actions will satisfy the requirements? (Choose two. )

Options:

A.

Configure recipient address verification.

B.

Configure inbound recipient policies.

C.

Configure outbound recipient policies.

D.

Configure access control rules.

Question 5

You are building a FortiGala cluster which is stretched over two locations. The HA connections for the cluster are terminated on the data centers. Once the FortiGates have booted, they do form a cluster. The network operators inform you that CRC eoors are present on the switches where the FortiGAtes are connected.

What would you do to solve this problem?

Options:

A.

Replace the caables where the CRC errors occur.

B.

Change the ethertype for the HA packets.

C.

Set the speedduplex setting to 1 Gbps /Full Duplex.

D.

Place the HA interfaces in dedicated VLANs.

Question 6

You want to manage a FortiCloud service. The FortiGate shows up in your list devices on the FortiCloud Web site, but all management functions are either missing or grayed out.

Which statement a correct in this scenario?

Options:

A.

The managed FcrtGate a running a version of ForflOS that is either too new or too for FortCloud.

B.

The managed FortiGate requires that a FortiCloud management license be purchased and applied.

C.

You must manually configure system control-management on the FortiGate CLI and set the management type to fortiguard.

D.

The management tunnel mode on the managed FortiGate must be changed to normal.

Question 7

Exhibit

Click the Exhibit button.

A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.

However, FortiGates A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The IKE real time debug shows the output in the exhibit when site A is disconnected.

Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time?

Options:

A.

set enforce-unique-id disable

B.

set add-router enable

C.

set single-source disable

D.

set router-overlap allow

Question 8

Click the Exhibit button.

A FortiGate with the default configuration is deployed between two IP phones. FortiGate receives the INVITE request shown in the exhibit form Phone A (internal)to Phone B (external). Which two actions are taken by the FortiGate after the packet is received? (Choose two.)

Options:

A.

A pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49169 and 49170.

B.

a pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49l70 and 49171.

C.

The phone A IP address will be translated lo the WAN IP address in all INVITE header fields and the m: field of the SDP statement.

D.

The phone A IP address will be translated for the WAN IP address in all INVITE header fields and the SDP statement remains intact.

Question 9

Click the Exhibit button.

You have installed a FortiSandbox and configured it in your FortiMail. Referring to the exhibit, which two statements are correct? (Choose two.)

Options:

A.

FortiMail will cache the results for 30 minutes.

B.

FortiMail will wait for 30 minutes to obtain the scan results.

C.

If the FortiSandbox with IP 10.10 10 3 is not available, the e-mail will be checked by the FortiCloud Sandbox.

D.

If FortiMail is not able to obtain the results from the fortiGuard quenes. URls will not be checked by the FortiSandbox.

Exam Detail
Vendor: Fortinet
Exam Code: NSE8_811
Last Update: Dec 21, 2024
NSE8_811 Question Answers
Page: 1 / 2
Total 65 questions