Fortinet

NSE8_811 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 45-question bank.

Provider
Fortinet
Question bank
45
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE8_811, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Consider the following FortiGate configuration: Which command-line option for deep inspection SSL would have the FortiGate re-sign all untrusted self-signed certificates with the trusted Fortinet_CA_SSL certificate?

    Choose one answer.

    Question illustration 1
    • block
    • inspect
    • allow
    • ignore
  2. Question 2 · 1

    Refer to the exhibit. A FortiGate is configured for a dial-up IPsec VPN to allow multiple remote FortiGate devices to connect to it. However, FortiGate A and B have problems connecting to the VPN. Only one of them can be connected at a time. If site B tries to connect while site A is connected, site A is disconnected. The IKE real-time debug shows the output in the exhibit when site A is disconnected. Referring to the exhibit, which configuration setting should be executed in the dial-up configuration to allow both VPNs to be connected at the same time?

    Choose one answer.

    Question illustration 1
    • set route-overlap allow
    • set single-source disable
    • set enforce-unique-id disable
    • set add-route enable
  3. Question 3 · 1

    A customer wants to enable SYN flood mitigation in a FortiDDoS device. The FortiDDoS must reply with one SYN/ACK packet per SYN packet from a new source IP address. Which SYN flood mitigation mode must the customer use?

    Choose one answer.

    • SYN retransmission
    • SYN/ACK cookie
    • SYN cookie
    • ACK cookie
  4. Question 4 · 1

    Refer to the exhibit. You configured AV and Web filtering for your outgoing Internet connections. You later notice that not all Web sessions are being inspected and you start troubleshooting the problem. Referring to the exhibit, what can be causing this problem?

    Choose one answer.

    Question illustration 1
    • The Web session is using QUIC which is not inspected by the FortiGate.
    • There are problems with the connection to the Web filter servers, therefore the Web session cannot be categorized.
    • The SSL inspection options are not set to deep inspection.
    • Web filtering is not licensed; therefore, no inspection occurs.
  5. Question 5 · 1

    Refer to the exhibit. Given the configuration shown in the exhibit, which two statements are true? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • LAG-3 on switches on FS448D-A and FS448D-B may be connected to a single 802.3ad trunk on another device.
    • LAG-1 and LAG-2 should be connected to a 4-port single 802.3ad trunk on another device.
    • port13 and port14 on FS448D-A should be connected to port13 and port14 on FS448D-B.
    • LAG-1 and LAG-2 should be connected to a single 4-port 802.3ad interface on the FortiGate-A.
  6. Question 6 · 1

    A customer wants to integrate their on-premise FortiGate with their Azure infrastructure. Which two components must be in place to configure the Azure Fabric connector? (Choose two.)

    Choose all answers that apply.

    • FortiGate-VM virtual appliance deployed on-premise.
    • An inbound policy from the Azure FortiGate-VM virtual appliance.
    • An outbound policy from the Azure FortiGate-VM virtual appliance.
    • A FortiGate-VM virtual appliance deployed in Azure.
  7. Question 7 · 1

    An organization has one central site and three remote sites. A FortiSIEM has been installed on the central site and now all devices across the remote sites must be centrally monitored by the FortiSIEM at the central site. Which action will reduce the WAN usage by the monitoring system?

    Choose one answer.

    • Enable SD-WAN FEC (Forward Error Correction) on the FortiGate at the remote site.
    • Install both Supervisor and Collector on each remote site.
    • Install local Collectors on each remote site.
    • Disable real-time log upload on the remote sites.
  8. Question 8 · 1

    A customer is looking for a way to remove javascripts, macros and hyperlinks from documents traversing the network without affecting the integrity of the content. You propose to use the Content disarm and reconstruction (CDR) feature of the FortiGate. Which two considerations are valid to implement CDR in this scenario? (Choose two.)

    Choose all answers that apply.

    • The inspection mode of the FortiGate is not relevant for CDR to operate.
    • CDR is supported on HTTPS, SMTPS, and IMAPS if deep inspection is enabled.
    • CDR can only be performed on Microsoft Office Document and PDF files.
    • Files processed by CDR can have the original copy quarantined on the FortiGate.
  9. Question 9 · 1

    You want to manage a FortiGate with the FortiCloud service. The FortiGate shows up in your list of devices on the FortiCloud Web site, but all management functions are either missing or grayed out. Which statement is correct in this scenario?

    Choose one answer.

    • The management tunnel mode on the managed FortiGate must be changed to normal.
    • The managed FortiGate is running a version of FortiOS that is either too new or too old for FortiCloud.
    • The managed FortiGate requires that a FortiCloud management license be purchased and applied.
    • You must manually configure system central-management on the FortiGate CLI and set the management type to fortiguard.
  10. Question 10 · 1

    Refer to the exhibit. As shown in the exhibit, a FortiADC is load-balancing IPv4 traffic between two next-hop routers. The FortiADC does not know the IP addresses of the servers. Also, the FortiADC is doing Layer 7 content inspection and modification. In this scenario, which application delivery control is configured in the FortiADC?

    Choose one answer.

    Question illustration 1
    • Layer 3
    • Layer 4
    • Layer 7
    • Layer 2
  11. Question 11 · 1

    Refer to the exhibit. You are trying to configure Link-Aggregation Group (LAG), but ports A and B do not appear on the list of member options. Referring to the exhibit, which statement is correct in this situation?

    Choose one answer.

    Question illustration 1
    • The FortiGate interfaces are defective and require replacement.
    • The FortiGate model does not have an Integrated Switch Fabric (ISF).
    • The FortiGate model being used does not support LAG.
    • The FortiGate SFP+ slot does not have the correct module.
  12. Question 12 · 1

    You have deployed a FortiGate in NAT/Route mode as a Secure Web Gateway with a few IP-based authentication firewall policies. Your customer reports that some users now have different browsing permissions from what is expected. All these users are browsing using Internet Explorer through a Remote Desktop Connection to a Terminal Server. When you look at the FortiGate logs, the username for the Terminal Server IP is not consistent. Which action will correct this problem?

    Choose one answer.

    • Change the FSSO Polling mode to Windows NetAPI.
    • Configure FSSO Advanced with LDAP integration.
    • Install the TS/Citrix agent on the terminal server.
    • Make sure the Terminal Server is using the correct DNS server.
  13. Question 13 · 1

    Refer to the exhibit. While deploying a new FortiGate-VMX Security node, an administrator receives the error message shown in the exhibit. In this scenario, which statement is correct?

    Choose one answer.

    Question illustration 1
    • The NSX Manager is not able to connect on the FortiGate Service Manager RestAPI service.
    • The vCenter is not able to locate the FortiGate-VMX OVF file.
    • The FortiGate Service Manager does not have the proper permission to register the FortiGate-VMX Service.
    • The vCenter cannot connect to the FortiGate Service Manager.
  14. Question 14 · 1

    A customer is experiencing problems with a legacy L3/L4 firewall device and the IPv6 SIP VoIP traffic. Their device is dropping SIP packets, consequently, it cannot process SIP voice calls. Which solution will solve the customer's problem?

    Choose one answer.

    • Replace their legacy device with a FortiGate and deploy a FortiVoice to extract information from the body of the IPv6 SIP packet.
    • Deploy a FortiVoice and enable IPv6 SIP.
    • Deploy a FortiVoice and enable an IPv6 SIP session helper.
    • Replace their legacy device with a FortiGate and configure it to extract information from the body of the IPv6 SIP packet.
  15. Question 15 · 1

    Refer to the exhibit. A VPN IPsec is connecting the headquarters office (HQ) with a branch office (BO). OSPF is used to redistribute routes between the offices. After deployment, a server with IP address 10.10.10.35 located on the DMZ network of the BO FortiGate, was reported unreachable from hosts located on the LAN network of the same FortiGate. Referring to the exhibit, which statement is true?

    Choose one answer.

    Question illustration 1
    • The ICMP packets are being blocked by an implicit deny policy.
    • A directly connected subnet is being partially superseded by an OSPF redistributed subnet.
    • Enabling NAT on the VPN firewall policy will solve the problem.
    • The incoming access list should have an accept action instead of a deny action to solve the problem.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free