New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

View the exhibit, which contains a partial routing table, and then answer the question below.

Assuming all the appropriate firewall policies are configured, which of the following pings will FortiGate route? (Choose two.)

A.

Source IP address 10.1.0.24, Destination IP address 10.72.3.20.

B.

Source IP address 10.72.3.27, Destination IP address 10.1.0.52.

C.

Source IP address 10.72.3.52, Destination IP address 10.1.0.254.

D.

Source IP address 10.73.9.10, Destination IP address 10.72.3.15.

Refer to the exhibit, which contains the partial output of a diagnose command.

Based on the output, which two statements are correct? (Choose two.)

A.

Anti-replay is enabled

B.

The remote gateway IP is 10.200.4.1.

C.

DPD is disabled.

D.

Quick mode selectors are disabled.

Which of the following statements is true regarding a FortiGate configured as an explicit web proxy?

A.

FortiGate limits the number of simultaneous sessions per explicit web proxy user. This limit CANNOT be modified by the administrator.

B.

FortiGate limits the total number of simultaneous explicit web proxy users.

C.

FortiGate limits the number of simultaneous sessions per explicit web proxy user The limit CAN be modified by the administrator

D.

FortiGate limits the number of workstations that authenticate using the same web proxy user credentials. This limit CANNOT be modified by the administrator.

Which two statements about an auxiliary session are true? (Choose two.)

A.

With the auxiliary session setting disabled, only auxiliary sessions are offloaded.

B.

With the auxiliary session setting enabled, two sessions are created in case of routing change.

C.

With the auxiliary session setting enabled, ECMP traffic is accelerated to the NP6 processor.

D.

With the auxiliary session setting disabled, for each traffic path, FortiGate uses the same auxiliary session.

View the exhibit, which contains the output of a web diagnose command, and then answer the question below.

Which one of the following statements explains why the cache statistics are all zeros?

A.

The administrator has reallocated the cache memory to a separate process.

B.

There are no users making web requests.

C.

The FortiGuard web filter cache is disabled in the FortiGate’s configuration.

D.

FortiGate is using a flow-based web filter and the cache applies only to proxy-based inspection.

Refer to the exhibit, which contains the output of the diagnose vpn tunnel list.

Which command will capture ESP traffic for the VPN named DialUp_0?

A.

diagnose sniffer packet any ‘esp and host 10.200.3.2’

B.

diagnose sniffer packet any ‘ip proto 50’

C.

diagnose sniffer packet any ‘host 10.0.10.10’

D.

diagnose sniffer packet any ‘port 4500’

View the exhibit, which contains a partial web filter profile configuration, and then answer the question below.

Which action will FortiGate take if a user attempts to access www.dropbox.com, which is categorized as File Sharing and Storage?

A.

FortiGate will exempt the connection based on the Web Content Filter configuration.

B.

FortiGate will block the connection based on the URL Filter configuration.

C.

FortiGate will allow the connection based on the FortiGuard category based filter configuration.

D.

FortiGate will block the connection as an invalid URL.

Refer to exhibit, which contains the output of a BGP debug command.

Which statement explains why the state of the 10.200.3.1 peer is Connect?

A.

The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the OpenConfirm yet.

B.

The TCP session to 10.200.3.1 has not completed the three-way handshake.

C.

The local router is receiving the BGP keepalives from the peer, but it has not received a BGP prefix yet.

D.

The local router has received the BGP prefixes from the remote peer.