Question 6 of 119

You have enabled logging on your FortiGate device for Event logs and all Security logs, and you have set up logging to use the FortiGate local disk.

What is the default behavior when the local disk is full?

    Correct Answer: A

    When the local disk on a FortiGate device is full, logs are overwritten, and the only warning is issued when the log disk usage reaches the threshold of 95%. This is a measure to ensure continuous logging without manual intervention to clear the disk.

Question 7 of 119

Refer to the exhibit, which contains a Performance SLA configuration.

An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic.

Why is FortiGate not generating any traffic for the performance SLA?

    Correct Answer: B

    The FortiGate is not generating any traffic for the performance SLA because the 'Enable probe packets' switch is turned off. This feature must be enabled to allow FortiGate to send out probe packets, which are necessary for monitoring and measuring the performance of the specified servers. In this configuration, the probe packets are required to determine the connectivity and performance SLA metrics for the specified IP addresses.

Question 8 of 119

FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.

In this scenario, which statement about VLAN IDs is true?

    Correct Answer: B

    In a FortiGate operating in NAT mode, when configured with virtual LAN (VLAN) subinterfaces on the same physical interface, each VLAN subinterface must have a unique VLAN ID to avoid conflicts. VLAN IDs serve to segregate network traffic and ensure proper routing. Having two VLAN subinterfaces with the same VLAN ID on the same physical interface would cause ambiguity in network packet handling, thus they must be different.

Question 9 of 119

Refer to the exhibit to view the application control profile.

Users who use Apple FaceTime video conferences are unable to set up meetings.

In this scenario, which statement is true?

    Correct Answer: C

    In the provided application control profile, Apple FaceTime falls under the 'Excessive-Bandwidth' filter, which has been set to 'Block' as per the custom filter settings. This means that any application categorized under excessive bandwidth usage, including FaceTime, would be blocked. Therefore, users are unable to set up meetings using Apple FaceTime because it is being filtered and blocked by this custom filter.

Question 10 of 119

What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?

    Correct Answer: D

    Enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel causes FortiGate to automatically bring up the IPsec tunnel and keep it up, regardless of activity on the IPsec tunnel. This means that the tunnel will be maintained even if there is no interesting traffic, ensuring continuous connectivity.