Fortinet NSE 8 Written Exam (NSE8_811) Sample Questions:
1. You cannot the FortiGales default gateway 10.10.10 .1 from the FortiGate CLI. The FortiGate interface facing the default gateway is wan 1 and its IP address 10.10 .10 K74 During the troubleshooting, tests, you confirmed that you can plug other IP addresses in the 10.10.10. 0/24 subnet from the FortiGAte CLI without packets lost.
Which two CLI commands will help you to troubleshoot this problem? (Choose two.)
A) diagnose ip arp list
B) diagnose hardware deviceinfo nic wan1
C) diagnose debug flow filter saddr 10.10.10.1
diagnose debug flow trace start 10
D) diag sniffer packet wan1 'arp and host 10.10.10.1'
2. You want to manage a FortiCloud service. The FortiGate shows up in your list devices on the FortiCloud Web site, but all management functions are either missing or grayed out.
Which statement a correct in this scenario?
A) The managed FcrtGate a running a version of ForflOS that is either too new or too for FortCloud.
B) The management tunnel mode on the managed FortiGate must be changed to normal.
C) You must manually configure system control-management on the FortiGate CLI and set the management type to fortiguard.
D) The managed FortiGate requires that a FortiCloud management license be purchased and applied.
3. You have a customer experiencing problem with a legacy L3L4 firewall device and IPV6 SIP VoIP traffic. They devices is dropping SIP packets, consequently, it process SIP voice calls. Which solution would solve the customer's problem?
A) Replace their legacy device with a FortiGate and deploy a FortiVoice to extract information from the body of the IPv6 SIP packet.
B) Deploy a FortiVoice and enable IPv6 SIP.
C) Deploy a FortiVoice and enable an IPv6 SIP session helper.
D) Replace their legacy device with a FortiGate and configure it to extract information from the body of the
IPv6 SIP packet.
4. Exhibit
You created a custom health-check for your FortiWeb deployment.
Referring to the output shown in the exhibit, which statement is true?
A) The FortiWeb must receive an HTTP 200 response code from the server.
B) The FortiWeb must receive an RST packet from the server.
C) The FortiWeb must match the hash value of the page index html.
D) The FortiWeb must receive an ICMP Echo Request from the server.
5. You configure an outgoing firewall policy with a web filter for accessing the internet. The access to URL https// itacm.co and web belonging to the same category should be blocked. You notice that the Web server presents a certificate with CN=www acme.com. The www.it.acme site is as '' information Technology and the www.acme.com site is categorized as ''Business".
Which statements is correct in this scenario?
A) SSL inspection must be configured to deep-inspection: the category "information Technology "needs to be blocked.
B) Category :information Technology" needs to be blocked, the SNI takes precedence over the certificate name.
C) Category "information Technology" needs to blocked, the FortiGate is able to inspection the URL with HTTPS sessions.
D) Category "Business" need a to be block: the certificate name takes precedence over the SNI.
Solutions:
Question # 1 Answer: A,C | Question # 2 Answer: C | Question # 3 Answer: A | Question # 4 Answer: A | Question # 5 Answer: B |