Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

You can use Firebox System Manager to download a PCAP file that includes packet information about the protocols that manage traffic on your network.

A.

True

B.

False

You need to create an HTTP-proxy policy to a specific domain for software updates (example.com). The update site has multiple subdomains and dynamic IP addresses on a content delivery network. Which of these options is the best way to define the destination in your HTTP-proxy policy? (Select one.)

A.

Configure a host name for update.example.com.

B.

Configure an FQDN for *.example.com.

C.

Add IP addresses that correspond to each software update server in the domain.

D.

Create an alias for all subdomains and known IP addresses for example.com.

Which WatchGuard tools can you use to review the log messages generated by your Firebox? (Select three).

A.

Firebox System Manager > Traffic Monitor

B.

Fireware XTM Web UI > Traffic Monitor

C.

Firebox System Manager > Status Report

D.

Dimension > Log manager

E.

WatchGuard System Manager > Policy Manager

You have a privately addressed email server behind your Firebox. If you want to make sure that all traffic from this server to the Internet appears to come from the public IP address 203.0.113.25, regardless of policies, which from of NAT would you use? (Select one.)

A.

In the SMTP policy that handles traffic from the email server, select the option to apply dynamic NAT to all traffic in the policy and set the source IP address 203.0.113.25.

B.

Create a global dynamic NAT rule for traffic from the email server and set the source IP address to 203.0.113.25.

C.

Create a static NAT action for traffic to the email server, and set the source IP address to 203.0.113.25.

The policies in a default Firebox configuration do not allow outgoing traffic from optional interfaces.

A.

True

B.

False

How can you prevent connections to the Fireware Web UI from computers on optional interface Eth2? (Select one.)

A.

Remove Eth2 from the Any-Optional alias.

B.

Remove Any-Optional from the To list of the WatchGuard Web UI policy.

C.

Remove Any-Optional from the From list of the WatchGuard policy.

D.

Remove Any-Optional from the To list of the WatchGuard policy

E.

Remove Any-Optional from the From list of the WatchGuard Web UI policy

If you disable the Outgoing policy, which policies must you add to allow trusted users to connect to commonly used websites? (Select three.)

A.

HTTP port 80

B.

NAT policy

C.

FTP port 21

D.

HTTPS port 443

E.

DNS port 53

While troubleshooting a branch office VPN tunnel, you see this log message:

2014-07-23 12:29:15 iked (203.0.113.10<->203.0.113.20) Peer proposes phase one encryption 3DES, expecting AES

What settings could you modify in the local device configuration to resolve this issue? (Select one.)

A.

BOVPN Gateway settings

B.

BOVPN-Allow policies

C.

BOVPN Tunnel settings

D.

BOVPN Tunnel Route settings

What is one reason that users could see a certificate warning in their web browsers when they connect to Fireware XTM Web UI? (Select one.)

A.

The Firebox or XTM device uses the default self-signed certificate.

B.

The authentication server does not respond after three minutes.

C.

The user has been previously added to the Blocked Sites list.

D.

The user or group is not present in the Firebox User database.

When you configure the Global Application Control action, it is automatically applied to all policies.

A.

True

B.

False