Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

Refer to the exhibit, which shows the output of a BGP summary.

What two conclusions can you draw from this BGP summary? (Choose two.)

A.

External BGP (EBGP) exchanges routing information.

B.

The BGP session with peer 10. 127. 0. 75 is established.

C.

The router 100. 64. 3. 1 has the parameter bfd set to enable.

D.

The neighbors displayed are linked to a local router with the neighbor-range set to a value of 4.

Full Access
Question # 5

Refer to the exhibit, which contains information about an IPsec VPN tunnel.

What two conclusions can you draw from the command output? (Choose two.)

A.

Dead peer detection is set to enable.

B.

The IKE version is 2.

C.

Both IPsec SAs are loaded on the kernel.

D.

Forward error correction in phase 2 is set to enable.

Full Access
Question # 6

You want to improve reliability over a lossy IPSec tunnel.

Which combination of IPSec phase 1 parameters should you configure?

A.

fec-ingress and fec-egress

B.

Odpd and dpd-retryinterval

C.

fragmentation and fragmentation-mtu

D.

keepalive and keylive

Full Access
Question # 7

Exhibit.

Refer to the exhibit, which contains the partial interface configuration of two FortiGate devices.

Which two conclusions can you draw from this con figuration? (Choose two)

A.

10.1.5.254 is the default gateway of the internal network

B.

On failover new primary device uses the same MAC address as the old primary

C.

The VRRP domain uses the physical MAC address of the primary FortiGate

D.

By default FortiGate B is the primary virtual router

Full Access
Question # 8

Refer to the exhibit, which shows an error in system fortiguard configuration.

What is the reason you cannot set the protocol to udp in config system fortiguard?

A.

FortiManager provides FortiGuard.

B.

fortiguard-anycast is set to enable.

C.

You do not have the corresponding write access.

D.

udp is not a protocol option.

Full Access
Question # 9

Which two statements about the Security fabric are true? (Choose two.)

A.

FortiGate uses the FortiTelemetry protocol to communicate with FortiAnatyzer.

B.

Only the root FortiGate sends logs to FortiAnalyzer

C.

Only FortiGate devices with configuration-sync receive and synchronize global CMDB objects that the toot FortiGate sends

D.

Only the root FortiGate collects network topology information and forwards it to FortiAnalyzer

Full Access
Question # 10

Which ADVPN configuration must be configured using a script on fortiManager, when using VPN Manager to manage fortiGate VPN tunnels?

A.

Enable AD-VPN in IPsec phase 1

B.

Disable add-route on hub

C.

Configure IP addresses on IPsec virtual interlaces

D.

Set protected network to all

Full Access
Question # 11

Which two statements about metadata variables are true? (Choose two.)

A.

You create them on FortiGate

B.

They apply only to non-firewall objects.

C.

The metadata format is $.

D.

They can be used as variables in scripts

Full Access
Question # 12

Exhibit.

Refer to the exhibit, which shows the output from the webfilter fortiguard cache dump and webfilter categories commands.

Using the output, how can an administrator determine the category of the training.fortinet.comam website?

A.

The administrator must convert the first three digits of the IP hex value to binary

B.

The administrator can look up the hex value of 34 in the second command output.

C.

The administrator must add both the Pima in and Iphex values of 34 to get the category number

D.

The administrator must convert the first two digits of the Domain hex value to a decimal value

Full Access
Question # 13

Exhibit.

Refer to the exhibit, which shows a partial touting table

What two concisions can you draw from the corresponding FortiGate configuration? (Choose two.)

A.

IPSec Tunnel aggregation is configured

B.

net-device is enabled in the tunnel IPSec phase 1 configuration

C.

OSPI is configured to run over IPSec.

D.

add-route is disabled in the tunnel IPSec phase 1 configuration.

Full Access
Question # 14

Refer to the exhibit, which shows a network diagram.

Which IPsec phase 2 configuration should you impalement so that only one remote site is connected at any time?

A.

Set route-overlap to allow.

B.

Set single-source to enable

C.

Set route-overlap to either use—new or use-old

D.

Set net-device to enable

Full Access
Question # 15

You want to configure faster failure detection for BGP

Which parameter should you enable on both connected FortiGate devices?

A.

Ebgp-enforce-multihop

B.

bfd

C.

Distribute-list-in

D.

Graceful-restart

Full Access