A FortiGate devices has two VDOMs in NAT/route mode. Which of the following solutions can be implemented by a network administrator to route traffic between the two
VDOMs.(Choose two)
A. Interconnect and configure an external physical interface in one VDOM to another physical interface in the second VDOM.
B. Configure both VDOMs to share the same table.
C. Use the inter-VDOMs links automatically created between all VDOMS.
D. Manually create and configured an inter-VDOM link between yours.
正解:A,D
質問 2:
If you have lost your password for the "admin" account on your FortiGate, how should you reset it?
A. Reboot the FortiGate. Via the local console, during the boot loader, use the menu to format the flash disk and reinstall the firmware. Then you can log in with the default password.
B. Reboot the FortiGate. Via the local console, during the boot loader, use the menu to log in as "maintainer" and enter the CLI commands to set the password for the "admin" account.
C. Power off the FortiGate. After several seconds, restart it. Via the local console, within 30 seconds after booting has completed, log in as "maintainer" and enter the CLI commands to set the password for the "admin" account.
D. Log in with another administrator account that has "super_admin" profile permissions, then reset the password for the "admin" account.
正解:C
質問 3:
Which of the following are operating mode supported in FortiGate devices? (Choose two)
A. Transparent
B. NAT/route
C. Offline inspection
D. Proxy
正解:A,B
質問 4:
In "diag debug flow" output, you see the message "Allowed by Policy-1: SNAT". Which is true?
A. The packet matched the topmost policy in the list of firewall policies.
B. The policy allowed the packet and applied session NAT.
C. The packet matched a firewall policy, which allows the packet and skips UTM checks
D. The packet matched the firewall policy whose policy ID is 1.
正解:D
質問 5:
Review the IKE debug output for IPsec shown in the exhibit below.
Which statements is correct regarding this output?
A. The output captures the dead peer detection messages.
B. The output captures the dead gateway detection packets.
C. The output is a phase 2 negotiation.
D. The output is a phase 1 negotiation.
正解:A