Question 6 of 127

An administrator has configured central DNAT and virtual IPs. Which of the following can be selected in the firewall policy Destination field?

    Correct Answer: B

    When central DNAT and virtual IPs are configured, the correct option for the firewall policy Destination field is the mapped IP address object of the VIP object. Central DNAT involves translating the destination address of packets to a different address as defined by the virtual IP object. Therefore, in the firewall policy, the mapped IP address of the VIP object should be selected as the destination.

Question 7 of 127

An administrator needs to strengthen the security for SSL VPN access. Which of the following statements are best practices to do so? (Choose three.)

    Correct Answer: B, C, E

    To strengthen the security for SSL VPN access, configuring host restrictions by IP or MAC address ensures that only authorized devices are allowed to connect. Using two-factor authentication with security certificates adds an additional layer of security, making it harder for unauthorized users to gain access. Implementing a client integrity check (host-check) ensures that the connecting device meets certain security standards before allowing access. These best practices help secure the SSL VPN access effectively.

Question 8 of 127

Which statement about FortiGuard services for FortiGate is true?

    Correct Answer: B

    The correct statement is that antivirus signatures are downloaded locally on FortiGate. This ensures that FortiGate can perform antivirus scanning efficiently and without needing constant access to external resources. The other options are incorrect because the web filtering database is not downloaded locally, FortiGate does not use UDP ports 53 or 8888 for IPS updates (it uses TCP ports instead), and while FortiAnalyzer has many uses, it is not configured as a local FDN for providing antivirus and IPS updates.

Question 9 of 127

Which of the following route attributes must be equal for static routes to be eligible for equal cost multipath (ECMP) routing? (Choose two.)

    Correct Answer: B, D

    For static routes to be eligible for equal cost multipath (ECMP) routing, the routes must have the same metric and cost. The metric is a value used by routing protocols to determine the best path to a destination. Cost is often another term for metric specifically in certain routing protocols. Having the same priority and distance is not necessary for ECMP.

Question 10 of 127

View the exhibit.

Based on this output, which statements are correct? (Choose two.)

    Correct Answer: A, C

    The global configuration is synchronized between the primary and secondary FortiGate devices, as indicated by the matching checksums in the 'global' section. The all VDOM is not synchronized between the primary and secondary FortiGate devices, as indicated by the differing checksums in the 'all' section. The root VDOM checksum differences indicate potential configuration issues, but the lack of synchronization, especially in the 'all' section, is a key indicator that the synchronization is not consistent. Therefore, the most accurate conclusions are that the global configuration is synchronized, while the all VDOM is not.