An administrator has a requirement to keep an application session from timing out on port 80. What
two changes can the administrator make to resolve the issue without affecting any existing services
running through FortiGate? (Choose two.)
BC
In which two ways can RPF checking be disabled? (Choose two )
CD
Explanation:
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD33955
Refer to the exhibit to view the application control profile.
Based on the configuration, what will happen to Apple FaceTime?
A
Which three CLI commands can you use to troubleshoot Layer 3 issues if the issue is in neither the
physical layer nor the link layer? (Choose three.)
BCD
Which two VDOMs are the default VDOMs created when FortiGate is set up in split VDOM mode?
(Choose two.)
AD
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/758820/split-task-vdom-
mode
Refer to the exhibit.
The exhibit contains a network interface configuration, firewall policies, and a CLI console
configuration.
How will FortiGate handle user authentication for traffic that arrives on the LAN interface?
C
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When
visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP
websites, the browser does not report errors.
What is the reason for the certificate warning errors?
C
Explanation:
Reference:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD41394
Which two statements are true about the RPF check? (Choose two.)
AD
Explanation:
Reference:
https://www.programmersought.com/article/16383871634/
An organizations employee needs to connect to the office through a high-latency internet
connection.
Which SSL VPN setting should the administrator adjust to prevent the SSL VPN negotiation failure?
B
Refer to the exhibit.
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The
administrator has determined that phase 1 fails to come up. The administrator has also re-entered
the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration
changes will bring phase 1 up? (Choose two.)
AD
An administrator needs to configure VPN user access for multiple sites using the same soft
FortiToken. Each site has a FortiGate VPN gateway.
What must an administrator do to achieve this objective?
B
Refer to the exhibit.
The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0.1.10) pings
the IP address of Remote-FortiGate (10.200.3.1)?
D
An administrator needs to increase network bandwidth and provide redundancy.
What interface type must the administrator select to bind multiple FortiGate interfaces?
C
Explanation:
Reference:
https://forum.fortinet.com/tm.aspx?m=120324
Refer to the exhibit, which contains a static route configuration.
An administrator created a static route for Amazon Web Services.
What CLI command must the administrator use to view the route?
D
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/latest/administration-
guide/139692/routing-concepts
Which three statements are true regarding session-based authentication? (Choose three.)
ACD