ExamGecko
Home / Fortinet / NSE8_812 / List of questions
Ask Question

Fortinet NSE8_812 Practice Test - Questions Answers, Page 8

List of questions

Question 71

Report Export Collapse

You deployed a fully loaded FG-7121F in the data center and enabled sslvpn-load-balance. Based on the behavior of this feature which statement is correct?

Become a Premium Member for full access
  Unlock Premium Member

Question 72

Report Export Collapse

A customer is operating a FortiWeb cluster in a high volume active-active HA group consisting of eight FortiWeb appliances. One of the secondary members is handling traffic for one specific VIP.

What will happen with the traffic if that secondary FortiWeb appliance fails?

Become a Premium Member for full access
  Unlock Premium Member

Question 73

Report Export Collapse

An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the OCSP server.

Part of the FortiGate configuration is shown below:

Fortinet NSE8_812 image Question 13 6387767015903442402445

Based on this configuration, which authentication scenario will FortiGate deny?

Become a Premium Member for full access
  Unlock Premium Member

Question 74

Report Export Collapse

An administrator discovers that CPU utilization of a FortiGate-200F is high and determines that no traffic is being accelerated by hardware.

Why is no traffic being accelerated by hardware?

Become a Premium Member for full access
  Unlock Premium Member

Question 75

Report Export Collapse

A customer would like to improve the performance of a FortiGate VM running in an Azure D4s_v3 instance, but they already purchased a BYOL VM04 license.

Which two actions will improve performance the most without making a FortiGate license change? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 76

Report Export Collapse

Refer to the exhibit.

Fortinet NSE8_812 image Question 16 63877670159081297647045

An HTTPS access proxy is configured to demonstrate its function as a reverse proxy on behalf of the web server it is protecting. It verifies user identity, device identity, and trust context, before granting access to the protected source. It is assumed that the FortiGate EMS fabric connector has already been successfully connected.

You need to ensure that ZTNA access through the FortiGate will redirect users to the FortiAuthenticator to perform username/password and multifactor authentication to validate access prior to accessing resources behind the FortiGate.

In this scenario, which two further steps need to be taken on the FortiGate? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 77

Report Export Collapse

Refer to the exhibit, which shows a FortiGate configuration snippet.

Fortinet NSE8_812 image Question 17 6387767015914379638009

A customer in Costa Rica has a FortiGate with SD-WAN configured to use a VPN connection to the United States to browse the internet using a public IP from that country. They would like to enable the SD-WAN rule using a webhook.

Which configuration must be added to the FortiGate, and which type of HTTP request must be used to accomplish this? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 78

Report Export Collapse

Refer to the exhibit.

Fortinet NSE8_812 image Question 18 63877670159206294416729

The exhibit shows the topology a customer wants to implement using a flexible authentication scheme. Users connecting from trusted remote locations are authenticated using only their username/password when connecting to the SSLVPN FortiGate in the data center.

When connecting from the Untrusted Clients, users must authenticate using 2-factor authentication.

In this scenario, which RADIUS attribute can be used as a RADIUS policy selector on the FortiAuthenticator to accomplish this goal?

Become a Premium Member for full access
  Unlock Premium Member

Question 79

Report Export Collapse

Refer to the exhibits.

Fortinet NSE8_812 image Question 19 63877670159253168161330

You are configuring a Let's Encrypt certificate to enable SSL protection to your website. When FortiWeb tries to retrieve the certificate, you receive a certificate status failed, as shown below.

Fortinet NSE8_812 image Question 19 63877670159253168161330

Based on the Server Policy settings shown in the exhibit, which two configuration changes will resolve this issue? (Choose two.)

Become a Premium Member for full access
  Unlock Premium Member

Question 80

Report Export Collapse

Refer to the exhibit that shows VPN debugging output.

Fortinet NSE8_812 image Question 20 63877670159425038675614

The VPN tunnel between headquarters and the branch office is not being established.

What is causing the problem?

Become a Premium Member for full access
  Unlock Premium Member
Total 105 questions
Go to page: of 11
Search

Related questions