Download Fortinet Network Security Expert 8 Written Exam (NSE8 810 - FortiOS 5.6).NSE8_810.Pass4Sure.2019-02-19.60q.vcex

Vendor: Fortinet
Exam Code: NSE8_810
Exam Name: Fortinet Network Security Expert 8 Written Exam (NSE8 810 - FortiOS 5.6)
Date: Feb 19, 2019
File Size: 6 MB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Purchase
Coupon: EXAM_HUB

Discount: 20%

Demo Questions

Question 1
  
Click the Exhibit button.  
You are working on an entry level model FortiGate that has been configured in flow-based inspection mode with various settings optimized for performance. It appears that the main Internet firewall policy is using the antivirus profile labelled default. Your customer has found that some virus samples are not being caught by the FortiGate.  
Referring to the exhibit, what is causing the problem?
  1. The set default-db configuration was set to extreme.
  2. The set options scan configuration items should have been changed to set options scan avmonitor.
  3. The default AV profile was modified to use quick scan-mode.
  4. The mobile-malware-db configuration was set to enable.
Correct answer: C
Question 2
Click the Exhibit button.  
  
Referring to the exhibit, which two statements are true? (Choose two.)
  1. port13 and port14 on FS448D-A should be connected to port13 and port14 on FS448D-B.
  2. LAG-1 and LAG-2 should be connected to a single 4-port 802.3ad interface on the FortiGate-A.
  3. LAG-3 on switches on FS448D-A and FS448D-B may be connected to a single 802.3ad trunk on another device.
  4. LAG-1 and LAG-2 should be connected to a 4-port single 802.3ad trunk on another device.
Correct answer: BC
Question 3
  
Click the Exhibit button.  
You created a custom health-check for your FortiWeb deployment.  
Referring to the output shown in the exhibit, which statement is true?
  1. The FortiWeb must receive an RST packet from the server.
  2. The FortiWeb must receive an HTTP 200 response code from the server.
  3. The FortiWeb must receive an ICMP Echo Request from the server.
  4. The FortiWeb must match the hash value of the page index html.
Correct answer: BC
Question 4
A company has just deployed a new FortiMail in gateway mode. The administrator is asked to strengthen e-mail protection by applying the policies shown below. 
-E-mail can only be accepted if a valid e-mail account exists.  
-Only authenticated users can send e-mails out.  
Which two actions will satisfy the requirements? (Choose two.)
  1. Configure recipient address verification.
  2. Configure inbound recipient policies.
  3. Configure outbound recipient policies.
  4. Configure access control rules.
Correct answer: AD
Question 5
Click the Exhibit button.  
  
Your company has two data centers (DC) connected using a Layer 3 network. Servers in farm A need to connect to servers in farm B as though they all were in the same Layer 2 segment. What would be configured on the FortiGates on each DC to allow such connectivity?
  1. Create an IPsec tunnel with transport-mode encapsulation.
  2. Create an IPsec tunnel with tunnel-mode encapsulation.
  3. Create an IPsec tunnel with VXLAN encapsulation.
  4. Create an IPsec tunnel with VLAN encapsulation.
Correct answer: C
Question 6
Click the Exhibit button.  
You configured an IPsec tunnel to a branch office. Now you want to make sure that the encryption of the tunnel is offloaded to hardware.  
Referring to the exhibit, which statement is true? 
  
  1. Incoming and outgoing traffic is offloaded.
  2. Outgoing traffic is offloaded; you cannot determine if incoming traffic is offloaded at this time.
  3. Traffic is not offloaded.
  4. Outgoing traffic is offloaded; incoming traffic not offloaded.
Correct answer: D
Question 7
You want to access the JSON API on FortiManager to retrieve information on an object.  
In this scenario, which two methods will satisfy the requirement? (Choose two.)
  1. Make a call with the Web browser on your workstation.
  2. Make a call with the SoapUPI API tool on your workstation.
  3. Download the WSDL file from FortiManager administration GUI.
  4. Make a call with the curl utility on your workstation.
Correct answer: CD
Question 8
You have a customer with a SCADA environmental control device that is triggering a false-positive IPS alert whenever the device’s Web GUI is accessed. You cannot seem to create a functional custom IPS filter to exempt this behavior, and it appears that the device is so old that it does not have HTTPS support.  
You need to prevent the false positive IPS alerts from occuring.  
In this scenario, which two actions would accomplish this task? (Choose two.)
  1. Create a very granular firewall policy for that device’s IP address which does not perform IPS scanning.
  2. Reconfigure the FortiGate to operate in proxy-based inspection mode instead of flow-based.
  3. Create a URL filter with the Exempt action for that device’s IP address.
  4. Change the relevant firewall policies to use SSL certificate-inspection instead of SSL deep-inspection.
Correct answer: AD
Question 9
Click the Exhibit button.  
A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.  
However, FortiGates A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The IKE real time debug shows the output in the exhibit when site A is disconnected.  
Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time? 
  
  1. set enforce-unique-id disable
  2. set add-route enable
  3. set single-source disable
  4. set route-overlap allow
Correct answer: D
Question 10
Click the Exhibit button. The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb. Which statement represents the purpose of this policy?  
  
  1. The policy redirects all HTTP URLs to HTTPS.
  2. The policy redirects all HTTPS URLs to HTTP.
  3. The policy redirects only HTTPS URLs containing ^/(.*)$ string to HTTP.
  4. The policy redirects only HTTPS URLs containing ^/(.*)$ string to HTTPS.
Correct answer: A
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!