Questions for the NSE8-811 were updated on : Nov 14 ,2024
Refer to the exhibit.
The exhibit shows a full-mesh topology between FortiGate and FortiSwitch devices. To deploy this
configuration, two requirements must be met:
20 Gbps full duplex connectivity is available between each FortiGate and the FortiSwitch devices
The FortiGate HA must be in AP mode
Referring to the exhibit, what are two actions that will fulfill the requirements? (Choose two.)
AC
You want to manage a FortiCloud service. The FortiGate shows up in your list devices on the
FortiCloud Web site, but all management functions are either missing or grayed out.
Which statement a correct in this scenario?
C
Exhibit
Click the Exhibit button. The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb.
Which statement represents the purpose of this policy?
A
Explanation:
https://help.fortinet.com/fweb/581/Content/FortiWeb/fortiweb-
admin/application_delivery.htm#application_delivery_1557589163_940788
You are asked to add a FortiDDoS to the network to combat detected slow connection attacks such as
Slowloris.
Which prevention mode on FortiDDoS will protect you against this specific type of attack?
A
Explanation:
https://help.fortinet.com/fddos/4-3-0/FortiDDoS/Understanding_FortiDDoS_Prevention_Mode.htm
You are building a FortiGala cluster which is stretched over two locations. The HA connections for the
cluster are terminated on the data centers. Once the FortiGates have booted, they do form a cluster.
The network operators inform you that CRC eoors are present on the switches where the FortiGAtes
are connected.
What would you do to solve this problem?
B
Explanation:
https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-high-
availability/HA_failoverHeartbeat.htm#Heartbea
You want to access the JSON API on FortiManager to retrieve information on an object.
In this scenario, which two methods will satisfy the requirement? (Choose two.)
AD
Exhibit
You created a custom health-check for your FortiWeb deployment.
Referring to the output shown in the exhibit, which statement is true?
B
Click the exhibit.
You created an aggregate interface between your FortiGate and a switch consisting of two 1 Gbps
links as shown in the exhibit. However, the maximum bandwidth never exceeds. 1 Gbps and
employees are complaining that the network is slow. After troubleshooting, you notice only one
member interface is being used. The configuration for the aggregate interface is shown in the
exhibit.
In this scenario, which command will solve this problem?
C
Click the exhibit button.
A FortiGate device is configured to authenticate SSL VPN users using digital certificates. Part of the
FortiGate configuration is shown in the exhibit.
Which two statements are true in this scenario? (Choose two.)
AC
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD48218
https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/751987/ssl-vpn-with-ldap-
integrated-certificate-authentication
Click the Exhibit button.
Referring to the exhibit, which command-line option for deep inspection SSL would have the
FortiGate re-sign all untrusted self-signed certificates with the trusted Fortinet_CA_SSL certificate?
C
Explanation:
https://help.fortinet.com/cli/fos60hlp/60/Content/FortiOS/fortiOS-cli-ref/config/firewall/ssl-ssh-
profile.htm
Exhibit
Click the Exhibit button.
A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGates to connect to it.
However, FortiGates A and B have problems connecting to the VPN. Only one of them can be
connected at a time. If site B tries to connect white site A is connected, site A is disconnected. The
IKE real time debug shows the output in the exhibit when site A is disconnected.
Which configuration setting should be executed in the dial-up configuration to allow both VPNs to be
connected at the same time?
D
Explanation:
https://docs.fortinet.com/document/fortigate/6.0.0/cli-reference/487941/vpn-ipsec-phase2-
interface-phase2
A customer wants to enable SYN Rood mitigation in a FortiDDoS device. The FortiDDoS must reply
with one SYN/ACK packet per SYN packet ftom a new source IP address. Which SYN packet from a
new source IP address.
Which SYN flood mitigation mode must the customer use?
A
Click the Exhibit button.
You configured AV and Web filtering for your outgoing Internet connections. You later noticed that
not all Web sessions are being inspected and you start troubleshooting the problem.
Referring to the exhibit, what would cause this problem?
A
You are administrating the FortiGate 5000 and FortiGate 7000 series products. You want to access the
HTTPS GU of the blade located n logical slot of the secondary chassis in a high-availability cluster.
Which URL will accomplish this task?
D
Click the Exhibit button.
Referring to the exhibit, which two statements are true? (Choose two.)
AC
Explanation:
https://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-managing-
fortiswitch/Stacking.htm