Fortinet

NSE8_812 practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 49-question bank.

Provider
Fortinet
Question bank
49
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for NSE8_812, a certification listed under Fortinet. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Fortinet. The certification credential is issued by Fortinet, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Review the VPN configuration shown in the exhibit. What is the Forward Error Correction behavior if the SD-WAN network traffic download is 500 Mbps and has 8% of packet loss in the environment?

    Choose one answer.

    Question illustration 1
    • 1 redundant packet for every 10 base packets
    • 3 redundant packet for every 5 base packets
    • 2 redundant packet for every 8 base packets
    • 3 redundant packet for every 9 base packets
  2. Question 2 · 1

    Refer to the exhibit. You have deployed a security fabric with three FortiGate devices as shown in the exhibit. FGT_2 has the following configuration: FGT_1 and FGT_3 are configured with the default setting. Which statement is true for the synchronization of fabric-objects?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • Objects from the FortiGate FGT_2 will be synchronized to the upstream FortiGate
    • Objects from the root FortiGate will only be synchronized to FGT_2
    • Objects from the root FortiGate will not be synchronized to any downstream FortiGate
    • Objects from the root FortiGate will only be synchronized to FGT_3
  3. Question 3 · 1

    Refer to the CLI output: Given the information shown in the output, which two statements are correct? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    • Geographical IP policies are enabled and evaluated after local techniques
    • Attackers can be blocked before they target the servers behind the FortiWeb
    • The IP Reputation feature has been manually updated
    • An IP address that was previously used by an attacker will always be blocked
    • Reputation from blacklisted IP addresses from DHCP or PPPoE pools can be restored
  4. Question 4 · 1

    Refer to the exhibit. You are deploying a FortiGate 6000F. The device should be directly connected to a switch. In the future, a new hardware module providing higher speed will be installed in the switch, and the connection to the FortiGate must be moved to this higher-speed port. You must ensure that the initial FortiGate interface connected to the switch does not affect any other port when the new module is installed and the new port speed is defined. How should the initial connection be made?

    Choose one answer.

    Question illustration 1
    • Connect the switch on any interface between ports 21 to 24
    • Connect the switch on any interface between ports 25 to 28
    • Connect the switch on any interface between ports 1 to 4
    • Connect the switch on any interface between ports 5 to 8
  5. Question 5 · 1

    You are designing a setup where the FortiGate device is connected to two upstream ISPs using BGP. Part of the requirement is that you must be able to refresh the route advertisements manually without disconnecting the BGP neighborships. Which feature must you enable on the BGP neighbors to accomplish this goal?

    Choose one answer.

    • Graceful-restart
    • Deterministic-med
    • Synchronization
    • Soft-reconfiguration
  6. Question 6 · 1

    Refer to the exhibit, which shows a Branch1 configuration and routing table. In the SD-WAN implicit rule, you do not want the traffic load balance for the overlay interface when all members are available. In this scenario, which configuration change will meet this requirement?

    Choose one answer.

    Question illustration 1
    • Change the load-balance-mode to source-ip-based.
    • Create a new static route with the internet sdwan-zone only.
    • Configure the cost in each overlay member to 10.
    • Configure the priority in each overlay member to 10.
  7. Question 7 · 1

    Refer to the exhibits. GUI Access - Configuration - Topology - An administrator has configured a FortiGate and FortiAuthenticator for two-factor authentication with FortiToken push notifications for their SSL VPN login. Upon initial review of the setup, the administrator has discovered that the customers can manually type in their two-factor code and authenticate but push notifications. Based on the information given in the exhibits, what must be done to fix this?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    Question illustration 3
    • On FG-1 port1, the ftm access protocol must be enabled.
    • FAC-1 must have an internet routable IP address for push notifications.
    • On FG-1 CLI, the ftm-push server setting must point to 100.64.1.41.
    • On FAC-1, the FortiToken public IP setting must point to 100.64.1.41.
  8. Question 8 · 1

    Refer to the exhibit. A customer has deployed a FortiGate 300E with virtual domains (VDOMs) enabled in the multi-VDOM mode. There are three VDOMs: Root is for management and internet access, while VDOM 1 and VDOM 2 are used for segregating internal traffic. AccountVInk and SalesVInk are standard VDOM links in Ethernet mode. Given the exhibit, which two statements below about VDOM behavior are correct? (Choose two.)

    Choose one answer.

    Question illustration 1
    • You can apply OSPF routing on the VDOM link in either PPP or Ethernet mode
    • Traffic on AccountVInk and SalesVInk will not be accelerated
    • The VDOM links are in Ethernet mode because they have IP addressed assigned on both sides
    • Root VDOM is an Admin type VDOM, while VDOM 1 and VDOM 2 are Traffic type VDOMs
    • OSPF routing can be configured between VDOM 1 and Root VDOM without any configuration changes to AccountVInk
  9. Question 9 · 1

    You are responsible for recommending an adapter type for NICs on a FortiGate VM that will run on an ESXi Hypervisor. Your recommendation must consider performance as the main concern, cost is not a factor. Which adapter type for the NICs will you recommend?

    Choose one answer.

    • Native ESXi Networking with E1000
    • Virtual Function (VF) PCI Passthrough
    • Native ESXi Networking with VMXNET3
    • Physical Function (PF) PCI Passthrough
  10. Question 10 · 1

    You are deploying a FortiExtender (FEX) on a ForiGate-60F. The FEX will be managed by the FortiGate. You anticipate high utilization. The requirement is to minimize the overhead on the device for WAN traffic. Which action achieves the requirement in this scenario?

    Choose one answer.

    • Add a switch between the FortiGate and FEX.
    • Enable CAPWAP connectivity between the FortiGate and the FortiExtender
    • Change connectivity between the FortiGate and the FortiExtender to use VLAN Mode
    • Add a VLAN under the FEX-WAN interface on the FortiGate
  11. Question 11 · 1

    Refer to the exhibits. Exhibit A - Exhibit B - A customer wants to deploy 12 FortiAP 431F devices on high density conference center, but they do not currently have any PoE switches to connect them to. They want to be able to run them at full power while having network redundancy. From the FortiSwitch models and sample retail prices shown in the exhibit, which build of materials would have the lowest cost, while fulfilling the customer’s requirements?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • 1x FortiSwitch 248E-FPOE
    • 2x FortiSwitch 224E-POE
    • 2x FortiSwitch 248E-FPOE
    • 2x FortiSwitch 124E-FPOE
  12. Question 12 · 1

    Refer to the exhibits. Exhibit A - Exhibit B - A customer is looking for a solution to authenticate the clients connected to a hardware switch interface of a FortiGate 400E. Referring to the exhibits, which two conditions allow authentication to the client devices before assigning an IP address? (Choose two.)

    Choose all answers that apply.

    Question illustration 1
    Question illustration 2
    • FortiGate devices with NP6 and hardware switch interfaces cannot support 802.1X authentication
    • Devices connected directly to ports 3 and 4 can perform 802.1X authentication
    • Ports 3 and 4 can be part of different switch interfaces
    • Client devices must have 802.1X authentication enabled
  13. Question 13 · 1

    You want to use the MTA adapter feature on FortiSandbox in an HA-Cluster. Which statement about this solution is true?

    Choose one answer.

    • The configuration of the MTA Adapter Local Interface is different than on port1
    • The MTA adapter is only available in the primary node
    • The MTA adapter mode is only detection mode
    • The configuration is different than on a standalone device
  14. Question 14 · 1

    Refer to the exhibit showing the history logs from a FortiMail device. Which FortiMail email security feature can an administrator enable to treat these emails as spam?

    Choose one answer.

    Question illustration 1
    • DKIM validation in a session profile
    • Sender domain validation in a session profile
    • Impersonation analysis in an antispam profile
    • Soft fail SPF validation in an antispam profile
  15. Question 15 · 1

    Refer to the exhibits, which show a firewall policy configuration and a network topology. Configuration - Topology - An administrator has configured an inbound SSL inspection profile on a FortiGate device (FG-1) that is protecting a data center hosting multiple web pages. Given the scenario shown in the exhibits, which certificate will FortiGate use to handle requests to xyz.com?

    Choose one answer.

    Question illustration 1
    Question illustration 2
    • FortiGate will fall-back to the default Fortinet_CA_SSL certificate
    • FortiGate will reject the connection since no certificate is defined
    • FortiGate will use the Fortmet_CA_Untrusted certificate for the untrusted connection
    • FortiGate will use the first certificate in the server-cert list—the abc.com certificate

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free