Fortinet NSE 8 Written Exam (NSE8_811) NSE8_811 Prüfungsfragen mit Lösungen:
1. You have a customer experiencing problem with a legacy L3L4 firewall device and IPV6 SIP VoIP traffic. They devices is dropping SIP packets, consequently, it process SIP voice calls. Which solution would solve the customer's problem?
A) Deploy a FortiVoice and enable IPv6 SIP.
B) Replace their legacy device with a FortiGate and deploy a FortiVoice to extract information from the body of the IPv6 SIP packet.
C) Replace their legacy device with a FortiGate and configure it to extract information from the body of the
IPv6 SIP packet.
D) Deploy a FortiVoice and enable an IPv6 SIP session helper.
2. A company has just rolled out new remote sites and now you need to deploy a single firewall policy to all of these sites to allow Internet access using FortiManager. For this particular firewall policy, the source address object is called LAN, but its value will change according to the site the policy is being installed.
Which statement about creating the object LAN is correct?
A) Create a new object called LAN and promote it to the global database.
B) Create a new object called LAN and set meta-fields per remote site.
C) Create a new object called LAN and use it as a variable on a TCL script.
D) Create a new object called LAN and enable per-device mapping.
3. Click the exhibit.
You created an aggregate interface between your FortiGate and a switch consisting of two 1 Gbps links as shown in the exhibit. However, the maximum bandwidth never exceeds. 1 Gbps and employees are complaining that the network is slow. After troubleshooting, you notice only one member interface is being used. The configuration for the aggregate interface is shown in the exhibit.
In this scenario, which command will solve this problem?
A) config system interface
edit Agg1
set Algorithm L4
end
B) config system interface
edit Agg1
set lacp-mode active
end
C) config system interface
edit Agg1
set min-links 2
end
D) config system interface
edit Agg1
set weight 2
end
4. A FortOS devices is used for termination of VPNs for number of remote spoke VPN units (designated group A spokes) using a phase 1 main mode dial-up tunnel using pre-shared. Your company recently acquired another organization. You are asked establish VPN correctively for the newly acquired organization's sites which new devices will be provisioned (designated Group B spokes). Both exiting (Group A) and new (Group B) spoke units are dynamically addressed. You are asked to ensure that spokes from the acquired organization (Group B) have different access permission than your existing VPN spokes (Group A).
Which two solutions meet the represents for the new spoke group? (Choose two.)
A) Implement separate phase 1 dial-up aggressive mode tunnels with a distinct peer ID.
B) Implement a new phase 1 dial-up main mode tunnel with pre-shared keys and XAuth.
C) Implement a new phase 1 dial-up main mode tunnel with a different pre-shared key than the Group A
spokes.
D) Implement a new phase 1 dial-up main mode tunnel with certificate authentication.
5. Exhibit
Click the Exhibit button. The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb. Which statement represents the purpose of this policy?
A) The policy redirects all HTTP URLs to HTTPS.
B) The policy redirects only HTTPS URLs containing the ˆ/ (. *) S string to HTTP.
C) The policy redirects all HTTPS URLs to HTTP.
D) The pokey redirects only HTTP URLs containing theˆ/ ( .*)S string to HTTPS.
Fragen und Antworten:
| 1. Frage Antwort: B | 2. Frage Antwort: D | 3. Frage Antwort: A | 4. Frage Antwort: A,B | 5. Frage Antwort: A |






1220 Kundenbewertungen

