Marcos Avila
Test por , creado hace más de 1 año

Fortigate Test sobre LAB 2 - Firewall Policies Quiz, creado por Marcos Avila el 20/10/2017.

302
1
0
Marcos Avila
Creado por Marcos Avila hace más de 6 años
Cerrar

LAB 2 - Firewall Policies Quiz

Pregunta 1 de 10

1

What statement is true regarding the Policy Lookup feature?

Selecciona una de las siguientes respuestas posibles:

  • Searches matching policy based on input criteria

  • Allows traffic to pass through FortiGate based on input criteria, even when there is no firewall policy allowing it

  • Enables extended logging on the firewall policy based on input criteria

  • Creates packet capture in Wireshark format based on input criteria

Explicación

Pregunta 2 de 10

1

Which FortiGate interface does source device type enable device detection on?

Selecciona una de las siguientes respuestas posibles:

  • Both source interface and destination interface of the firewall policy

  • All interfaces of FortiGate

  • Destination interface of the firewall policy only

  • Source interface of the firewall policy only

Explicación

Pregunta 3 de 10

1

Which statements are true regarding device identification? (Choose two.)

Selecciona una o más de las siguientes respuestas posibles:

  • Agent-based (FortiCIient) devices use the HTTP user-agent header to identify devices.

  • Agentless devices are indexed by their MAC address.

  • Agent-based (FortiCIient) devices are tracked by their FortiCIient unique ID

  • Only agent—based device identification techniques are supported.

Explicación

Pregunta 4 de 10

1

Which statements correctly define Policy ID and policy Sequence number for firewall policies? (Choose two.)

Selecciona una o más de las siguientes respuestas posibles:

  • A policy sequence number defines the order in which rules are processed.

  • A policy ID number is required to modify a firewall policy from the CLI.

  • A policy ID number changes when policies are re-ordered.

  • A policy sequence number reflects the number of objects used in the firewall policy.

Explicación

Pregunta 5 de 10

1

Which statements are true regarding incoming and outgoing interfaces in firewall policies? (Choose two.)

Selecciona una o más de las siguientes respuestas posibles:

  • Multiple interfaces can be selected as incoming and outgoing interfaces.

  • An incoming interface is mandatory in a firewall policy, but an outgoing interface is optional.

  • Only the any interface can be chosen as an incoming interface.

  • A zone can be chosen as the outgoing interface.

Explicación

Pregunta 6 de 10

1

Examine the CLI configuration. What does this configuration do? (Choose two.)
config system setting
set ses—denied—traffic enable
end

Selecciona una o más de las siguientes respuestas posibles:

  • It creates a session for traffic being denied.

  • It sends an alert notification to the administrator upon detecting denied traffic.

  • It reduces the amount of logs generated by denied traffic.

  • A log message will only generate if there is a security event.

Explicación

Pregunta 7 de 10

1

What criteria does FortiGate use to match traffic to a firewall policy? (Choose two.)

Selecciona una o más de las siguientes respuestas posibles:

  • Source and destination interfaces

  • Logging settings

  • Security profiles

  • Network services

Explicación

Pregunta 8 de 10

1

Which statements are true regarding the By Sequence View for firewall policies? (Choose two.)

Selecciona una o más de las siguientes respuestas posibles:

  • Does not show the source interface column

  • ls still available even when the any interface is being used in one or more firewall policies

  • Lists firewall policies primarily by their policy sequence number

  • ls disabled if any firewall policy has its status set to disable

Explicación

Pregunta 9 de 10

1

What must be selected in the Source field of a firewall policy?

Selecciona una de las siguientes respuestas posibles:

  • At least one source user or user group object

  • At least one address object

  • At least one device object

  • At least one source user, one source device, and one source address object

Explicación

Pregunta 10 de 10

1

What statement is true regarding the Service setting in a firewall policy?

Selecciona una de las siguientes respuestas posibles:

  • It is optional to add a service in a firewall policy.

  • It matches the traffic by port number.

  • Only one service object can be added to the firewall policy.

  • Administrators cannot create custom services objects.

Explicación