Fortinet NSE 8 - Recertification Sample Questions:
1. A company has just rolled out new remote sites and now you need to deploy a single firewall policy to all of these sites to allow Internet access using FortiManager. For this particular firewall policy, the source address object is called LAN, but its value will change according to the site the policy is being installed.
Which statement about creating the object LAN is correct?
A) Create a new object called LAN and enable per-device mapping.
B) Create a new object called LAN and use it as a variable on a TCL script.
C) Create a new object called LAN and promote it to the global database.
D) Create a new object called LAN and set meta-fields per remote site.
2. The exhibit shows an explicit Web proxy configuration in a FortiGate device. The FortiGate is installed between a client with the IP address 172.16.10.4 and a Web server using port 80 with the IP address 10.10.3.4. The client Web browser is properly sending HTTP traffic to the FortiGate Web proxy IP address 172.16.10.254.
Which two sniffer commands will capture this HTTP traffic? (Choose two.)
A) diagnose sniffer packet any 'host 172.16.10.4 and port 8080' 3
B) diagnose sniffer packet any 'host 172.16.10.254 and host 10.10.3.4' 3
C) diagnose sniffer packet any 'host 172.16.10.4 and host 10.10.3.4' 3
D) diagnose sniffer packet any 'host 172.16.10.4 and host 172.16.10.254' 3
3. The wireless controller diagnostic output is shown on the exhibit.
Which three statements are true? (Choose three.)
A) There are no wireless clients connected to the guest wireless network.
B) An access control list applied to the VAP interface blocks Android devices.
C) Firewall policies using device types are blocking Android devices.
D) This is a CAPWAP control channel diagnostic command.
E) The "src-vis" process is active on the staff wireless network VAP interface.
4. A FortiGate deployment contains the following configuration:
What is the result of this configuration?
A) Route-maps from VDOM SERVICES are available in all other VDOMs
B) Route-maps for VDOM SERVICES are excluded from HA configuration synchronization
C) Route-maps are not configurable in VDOM SERVICES
D) Route-maps from the Root VDOM configuration are available in VDOM SERVICES
5. You are asked to design a secure solution using Fortinet products for a company. The company recently has Web servers that were exploited and defaced. The customer has also experienced Denial or Service due to SYN Flood attacks. Taking this into consideration, the customer's solution should have the following requirements:
- management requires network-based content filtering with man-in-the-
middle inspection
- the customer has no existing public key infrastructure but requires
centralized certificate management
- users are tracked by their active directory username without
installing any software on their hosts
- Web servers that have been exploited need to be protected from the OW ASP Top 10
- notification of high volume SYN Flood attacks when a threshold has
been triggered
Which three solutions satisfy these requirements? (Choose three.)
A) FortiWeb
B) FortiAuthenticator
C) FortiGate
D) FortiCiient
E) FortiDDOS
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: B,D | Question # 3 Answer: A,C,D | Question # 4 Answer: B | Question # 5 Answer: A,B,E |
We're so confident of our products that we provide no hassle product exchange.


By Wallis

