New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Note! Following NSE8_811 Exam is Retired now. Please select the alternative replacement for your Exam Certification. The new exam code is NSE8_812

Verified By IT Certified Experts

CertsTopics.com Certified Safe Files

Up-To-Date Exam Study Material

99.5% High Success Pass Rate

100% Accurate Answers

Instant Downloads

Exam Questions And Answers PDF

Try Demo Before You Buy

Certification Exams with Helpful Questions And Answers

Fortinet NSE 8 Written Exam (NSE8_811) Questions and Answers

Question 1

Click the Exhibit button.

A FortiGate with the default configuration is deployed between two IP phones. FortiGate receives the INVITE request shown in the exhibit form Phone A (internal)to Phone B (external). Which two actions are taken by the FortiGate after the packet is received? (Choose two.)

Options:

A.

A pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49169 and 49170.

B.

a pinhole will be opened to accept traffic sent to FortiGate's WAN IP address and ports 49l70 and 49171.

C.

The phone A IP address will be translated lo the WAN IP address in all INVITE header fields and the m: field of the SDP statement.

D.

The phone A IP address will be translated for the WAN IP address in all INVITE header fields and the SDP statement remains intact.

Buy Now
Question 2

Refer to the exhibit.

You are working on FortiGate 61E operating in flow-based inspection mode with various settings optimized for performance. The main Internet firewall policy is using the "default" antivirus profile. You found that some executable virus samples files downloaded over HTTP are not being blocked by the FortiGate.

Referring to the exhibit, how can this be fixed?

Options:

A.

Change the set scan-mode configuration to full.

B.

Disable the emulator feature.

C.

Change the set default-db configuration to extreme.

D.

Add set content-disarm enable to the configuration.

Question 3

Exhibit

Click the Exhibit button.

A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.

However, FortiGates A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The IKE real time debug shows the output in the exhibit when site A is disconnected.

Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time?

Options:

A.

set enforce-unique-id disable

B.

set add-router enable

C.

set single-source disable

D.

set router-overlap allow