Which statement about video filtering on FortiGate is true?
Which statement about video filtering on FortiGate is true?A . Full SSL Inspection is not required. B. It is available only on a proxy-based firewall policy. C. It inspects video files hosted on file sharing services. D. Video filtering FortiGuard categories are based on web filter FortiGuard categories.View AnswerAnswer: B...
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?A . The public key of the web server certificate must be installed on the browser. B. The web-server certificate must be installed on the browser....
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?A . It limits the scanning of application traffic to the DNS protocol only. B. It limits the scanning of application traffic to use parent signatures only. C. It limits...
Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)
Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)A . DNS B. ping C. udp-echo D. TWAMPView AnswerAnswer: C,D
Which of statement is true about SSL VPN web mode?
Which of statement is true about SSL VPN web mode?A . The tunnel is up while the client is connected. B. It supports a limited number of protocols. C. The external network application sends data through the VPN. D. It assigns a virtual IP address to the client.View AnswerAnswer: B...
Based on the exhibit, which configuration change can the administrator make to allow Twitter while blocking all other social networking sites?
Refer to exhibit. An administrator configured the web filtering profile shown in the exhibit to block access to all social networking sites except Twitter. However, when users try to access twitter.com, they are redirected to a FortiGuard web filtering block page. Based on the exhibit, which configuration change can the...
Which CLI command will display sessions both from client to the proxy and from the proxy to the servers?
Which CLI command will display sessions both from client to the proxy and from the proxy to the servers?A . diagnose wad session list B. diagnose wad session list | grep hook-pre&&hook-out C. diagnose wad session list | grep hook=pre&&hook=out D. diagnose wad session list | grep "hook=pre"&"hook=out"View AnswerAnswer: A
Given the interfaces shown in the exhibit. which two statements are true?
Refer to the exhibit. Given the interfaces shown in the exhibit. which two statements are true? (Choose two.)A . Traffic between port2 and port2-vlan1 is allowed by default. B. port1-vlan10 and port2-vlan10 are part of the same broadcast domain. C. port1 is a native VLAN. D. port1-vlan and port2-vlan1 can...
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?
What is the limitation of using a URL list and application control on the same firewall policy, in NGFW policy-based mode?A . It limits the scope of application control to the browser-based technology category only. B. It limits the scope of application control to scan application traffic based on application...
What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?
What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?A . FortiGate automatically negotiates different local and remote addresses with the remote peer. B. FortiGate automatically negotiates a new security association after the existing security association expires. C. FortiGate automatically negotiates different encryption and...