NSE5-MGT认证考试题库(含答案)_第1页
NSE5-MGT认证考试题库(含答案)_第2页
NSE5-MGT认证考试题库(含答案)_第3页
NSE5-MGT认证考试题库(含答案)_第4页
NSE5-MGT认证考试题库(含答案)_第5页
已阅读5页,还剩62页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

NSE5-MGT认证考试题库(含答案)

一、单选题

1.InadditiontothedefauItADOMs,anadministratorhascreatedanewADOMnamedT

rainingforFortiGatedevices.TheadministratorsentadeviceregistrationtoF

ortiManagerfromaremoteFortiGate.WhichoneofthefoIlowingstatementsistru

e?

AvBydefau11,theunregisteredFortiGatewiIIappearintherootADOM.

B、TheFortiGatewiIIbeautomaticaIIyaddedtotheTrainingADOM.

CvTheFortiManageradministratormustaddtheunregistereddevicemanuaIIyto

theunregistereddevicemanuaIIytotheTrainingADOMusingtheAddDevicewizard

DxTheFortiGatewiIIbeaddedautomaticaIIytothedefauItADOMnamedFortiGate.

答案:A

2.AnadministratorhasaddedaIIthedevicesinaSecurityFabricgrouptoFortiMa

nager.

HowdoestheadministratoridentifytherootFortiGate?

A、ByadoIIarsymboI($)attheendofthedevicename

B、ByanatsymboI()attheendofthedevicename

C、ByaQUESTIONNO:mark()attheendofthedevicename

D、ByanAsterisk(*)attheendofthedevicename

答案:D

3.AnadministratorwouIdIiketocreateanSD-WANdefauItstaticrouteforanewIy

createdSD-WAN

UsingtheFortiManagerGUI.Bothportlandport2arepartoftheSD-WANmemberinte

rfaces.

WhichinterfacemusttheadministratorseIectinthestaticroutedevicedrop-do

wnIist?

A、port2

B、virtuaI-wan-1ink

C、portl

D、auto-discovery

答案:B

4.WhatdoesapoIicypackagestatusofModifiedindicate?

A、FortiManagerisunabIetodeterminethepoIicypackagestatus

B、ThepoIicypackagewasneverimportedafteradevicewasregisteredonFortiMa

nager

C、ThePoIicyconfigurationhasbeenchangedonamanageddeviceandchangeshave

notyetbeenimportedintoFortiManager

D、ThePoIicypackageconfigurationhasbeenchangedonFortiManagerandchange

shavenotyetbeeninstaIIedonthemanageddevice.

答案:D

5.WhichconfigurationsettingforFortiGateispartofadevice-1eveIdatabase©

nFortiManager?

A、VIPandIPPooIs

B、FirewaIIpoIicies

CvSecurityprofiIes

D\Routing

答案:D

6.AnadministratorhasassignedagIobaIpoIicypackagetocustomADOMI.Thenthe

administrator

CreatesanewpoIicypackage,Fortinet,inthecustomADOMI.

WhichstatementaboutthegIobaIpoIicypackageassignmenttothenewIy-created

poIicypackage

Fortinetistrue?

AvWhenanewpoIicypackageiscreated,itautomaticaIIyassignsthegIobaIpoIi

ciestothenewpackage.

B、WhenanewpoIicypackageiscreated,youneedtoassignthegIobaIpoIicypacka

gefromthegIobaIADOM.

C、WhenanewpoIicypackageiscreated,youneedtoreappIythegIobaIpoIicypack

agetotheADOM.

D、WhenanewpoIicypackageiscreated,youcanseIecttheoptiontoassignthegIo

baIpoIiciestothenewpackage.

答案:A

7.WhatshouIdyouconsiderwhenenabIingMEAsonFortiManager?

A、AtIeasefiveavaiIabIeinterfacesonFortiManager

B、NumberofCPUsandamountofmemory

GFortiManagerpatibiIitywithXMLAPI

D、AtIeasttworoutingtabIes

答案:B

8.ViewthefoIIowingexhibit.

.DrwcN«nr

tLociiFmGMr

fR<a>o(e-F<MVGw

•tcxMp;ATl(Mjm

•SmtkttfXAT)

ShaicdPackage

IPv4PolicyInstallahonTarget

InstallationTaredfRanote-FortiGate

default.rootATHNlanagemcntJ

StudcntfNATl

tLocal-PortiGate

ShaiedPackage

IPv4PohqUMOnNameFro*To

InstallationTantets

default1ODRemoce-Fort>Gi(e(Stvdenl)PmgAccesspoet3portl

ODLociPFortiG皿root)

a

•ODRanoteFori>Oite(Student)WebportJportl

3・InsulationTargetsSourceDeviceporOportl

WhichoneofthefoIlowingstatementsistrueregardinginstaIIationtargetsinu

seInstaIIOncoIumn?

A、PoIicyseq=3wiIIbeinstaIIedontheTrainer[NAT]VDOMonIy

B、TheInstaIIOncoIumnvaIuerepresentssuccessfuIinstaIIationonthemanage

ddevices

C、Policyseq=3wiIIbenotinstaIIedonanymanageddevice

D、Policyseq=3wiIIbeinstaIIedonaIImanageddevicesandVDOMsthatareIisted

underInstaIIationTargets

答案:D

9.WhatmustyouspecifywhenyouconfigureanSD-WANusingcentraImanagement?

AvAtIeasttwomemberinterfaces

B、AFortinetSD-WANIicense

C、AtIeastonememberiinterface

D、AtIeastfourmemberinterfaces

答案:A

10.WhatisthepurposeofADOMrevisions?

A、TocreateSystemCheckpointsfortheFortiManagerconfiguration.

B、TosavethecurrentstateofthewhoIeADOM.

CvTosavethecurrentstateofaIIpolicypackagesandobjectsforanADOM.

DvTorevertindividuaIpoIicypackagesanddevice-leveIsettingsforamanaged

FortiGatebyrevertingtoaspecificADOMrevision

答案:c

11.HowdoesFortiManagerdetermineifamanageddeviceSyncStatusisOut-of-Syn

c?

A、ItparesthecurrentrevisionhistorywiththeFortiGateconfiguration.

B、ItparestheADOM-1eveIdatabasewiththeFortiGateconfiguration.

C、ItparestheprovisioningtempIatewiththeFortiGateconfiguration.

D、Itparesthedevice_1eveIdatabasewiththeFortiGateconfiguration.

答案:A

12.ViewthefoIlowingexhibit.

ImportDevice-Local-FortiGate[root]

Createanewpolicypackageforimport.

PolicyPackageNameLocal-FortiGate

Folderroot

PolicySelection

0ImportAll(3)

0SelectPoliciesandProfileGroupstoImport

ObjectSelection0Importonlypolicydependentobjects

QImportallobjects

AnadministratorisimportinganewdevicetoFortiManagerandhasseIectedthesh

ownoptions.

WhatwiIIhappeniftheadministratormakesthechangesandinstaIIsthemodified

poIicypackageonthis

ManagedFortiGate?

A、TheunusedobjectsthatarenottiedtothefirewaIIpoIicieswiIIbeinstaIIed

onFortiGate

B、TheunusedobjectsthatarenottiedtothefirewaIIpoIicieswiIIremainasrea

d-onIyIocaIIyonFortiGate

C、TheunusedobjectsthatarenottiedtothefirewaIIpoIiciesIocaIIyonFortiG

atewiIIbedeIeted

D、TheunusedobjectsthatarenottiedtothefirewaIIpoIiciesinpoIicypackage

wiIIbedeIetedfromtheFortiManagerdatabase

答案:c

13.AnadministratorwouIdIiketocreateanSD-WANusingcentraImanagement.

WhatstepsdoestheadministratorneedtoperformtocreateanSD-WANusingcentra

Imanagement?

AvFirstcreateanSD-WANfirewaIIpoIicy,addmemberinterfacestotheSD-WANte

mpIateandcreateastaticroute

B、YoumustspecifyagatewayaddresswhenyoucreateadefauItstaticroute

CvRemoveaIItheinterfacereferencessuchasroutesorpoIicies

DvEnabIeSD-WANcentraImanagementintheADOM,addmemberinterfaces,createa

staticrouteandSDWANfirewaIIpoIicies.

答案:D

14.WhichconfigurationsettingforFortiGateispartofanADOM-1eveIdatabase©

nFortiManager?

A、NSX-TServiceTempIate

B、SecurityprofiIes

GSNMP

DvRouting

答案:D

15.WhatwiIIbetheresuItofrevertingtoapreviousrevisionversionintherevis

ionhistory?

AvItwiIIinstaIIconfigurationchangestomanageddeviceautomaticaIIy

B、ItwiIItagthedevicesettingsstatusasAuto-Update

C、ItwiIIgenerateanewversionIDandremoveaIIotherrevisionhistoryversion

s

D、ItwiIImodifythedevice-1eveIdatabase

答案:D

16.WhichofthepurposeofthePoIicyCheckfeatureonFortiManager?

AvItprovidesremendationtobinesimiIarpoIicypackageswithinanADOMintoon

esingIepoIicypackage.

B、ItprovidesremendationforoptimizingpoIiciesinapoIicypackage.

C、ItmergesandcreatesdynamicmappingsfordupIicateobjectsusedinapoIicyp

ackage

DvItparesthepoIicypackageswiththerevisionhistory,andupdatespoIicypac

kagesintheADOMdatabase.

答案:B

17.Refertotheexhibit.

Starttoimportconfigfromdevice(Reinote-FoitiGate)vdoin(ro<

package(Remote-FortiGate)

HfirewalladdiTS$n,SUCCESS,H(name=REMOTE_SVBXET.oi<

Mfirewallpolicy”,SUCCESS,''(name=l,oid=990.newobject)**

**firewallpolicy''.FAIL,"(iiame=ID:2(#2),oid=991,reasoii=inter:

coutradictiou.detail:any<-port6)bindiiigfail)**

ReviewtheDownIoadImportReport.WhyisitfaiIingtoimportfirewaIIpoIicyID

2?

AvTheaddressobjectusedinpoIicyID2aIreadyexistsintheADOMdatabasewitha

nyastheinterfaceassociation,andconfIictswiththeaddressobjectiinterface

associationIocaIIyonFortiGate.

B、PolicyID2forthismanagedFortiGateaIreadyexistsonFortiManagerinpoIic

ypackagenamedRemote-FortiGate

C、PolicyID2doesnothaveAD0MInterfacemappingconfiguredonFortiManager

D、PoIicyID2isconfiguredfromtheinterfaceanytoport6.FortiManagerreject

stoimportthispoIicybecausetheanyinterfacedoesnotexistonFortiManager.

答案:A

18.ViewthefoIlowingexhibit:

ImportDevice-Local-FortiGate[root]

Whenimportingconfigurationfromthisdevice,allenabledinterfacesrequireamappingtoanADOM

Levelinterface.Note,thesameADOMLevelinterfacecanmaptodifferentinterfacesontheeachdev

DeviceInterfaceADOMInterface

portlWAN

port3LAN

✓Addmappingsforallunuseddeviceinterfaces_________________

AnadministratorusedthevaIueshownintheexhibitwhenimportingaLocaI-Forti

Gateinto

FortiManager.

WhatnamewiIIbeusedtodispIaythefirewaIIpoIicyforportl?

A、portlonFortiGateandWANonFortiManager

B、portlonbothFortiGateandFortiManager

C、WANzoneonFortiGateandWANzoneonFortiManager

DxWANzoneonFortiGateandWANinterfaceonFortiManager

答案:A

19.InadditiontothedefauItADOMs,anadministratorhascreatedanewADOMnamed

Trainingfor

FortiGatedevices.TheadministratorauthorizedtheFortiGatedeviceonFortiM

anagerusingtheFortinet

SecurityFabric.

Giventheadministrator'sactions,whichstatementcorrectIydescribestheexp

ectedresuIt?

A、TheFortiManageradministratormustaddtheauthorizeddevicetotheTrainin

gADOMusingtheAddDevicewizardonIy.

B、TheauthorizedFortiGatewiIIbeautomaticaIIyaddedtotheTrainingADOM.

C、TheauthorizedFortiGatewiIIappearintherootADOM.

D、TheauthorizedFortiGatecanbeaddedtotheTrainingADOMusingFortiGateFab

ricConnectors.

答案:c

20.AnadministratorwantstodeIeteanaddressobjectthatiscurrentIyreferenc

edinafirewaIIpoIicy.

Whatcantheadministratorexpecttohappen?

AvFortiManagerwiIInotaIIowtheadministratortodeIeteareferencedaddress

object

B、FortiManagerwiIIdisabIethestatusofthereferencedfirewaIIpoIicy

C\FortiManagerwiIIrepIacethedeIetedaddressobjectwiththenoneaddressob

jectinthereferencedFirewaIIpolicy

DvFortiManagerwiIIrepIacethedeIetedaddressobjectwithaIIaddressobject

inthereferencedfirewaIIpoIicy

答案:c

21.ViewthefoIlowingexhibit.

StartingLog(Runthedevice)

Startinstalling

LocabFortiGate$confiruserdevice

LooI-ForttGate(device)$editwmyd«vicc,,

newentry'mydevice/added

Loeal*FortiGat»(mydeviee)$nevt

MACaddressc>nnotbe0

Node_check_objectfaillformac00:00:00:00:00:00

Attribute'mac'value^OOrOOrOOcOOrOOrOO/checkingfail-33

Commandfail.Returncode1

Local-FortiGate(device)$end

Local-FortiGate$confiffirewallpolicy

Local-FortiGate(policy)$edit2

Newentry2'added

LocabFortiGate(2)$setname*Device_policy**

Lo€«l-FortiG«t<(2)$setuuidG4.・・

Loc«l-FortiGate(2)$s<tsreintiOport3"*

Local-FortiGate(2)$setdstintf"portl”

Local-FortiOate(2)$setsreaddr"air,

Lool-FortiGate(2)$setdstaddr

Local-FortiGate(2)$setactionaccept

Local-FortiGate(2)$setschedule"always**

Local-FortiGat«(2)$service"ALL”

Loc4il-FQrtiO«t«(2)$ckrvis."myd«5s”

Entrynotfoundindatasource

Valuepanoorrorboforofmyd«vico

Commandfail.Returncode-3

LocakFortiGate(2)$setnatenable

Local-FortiGate(2)$next

LoobFortiGate(policy)$end

WhichstatementistrueregardingthisfaiIedinstaIIationIog?

AvPoIicyID2isinstaIIedwithoutasourcedevice

B、PoIicyID2isinstaIIedwithoutasourceaddress

C\PoIicyID2wiIInotbeinstaIIed

D、PolicyID2isinstaIIedindisabIedstate

答案:A

22.Refertotheexhibit.

Starttoimportconfigfromdevice(LocakFortiGate)vdom(root)to

adom(My_ADOM),package(Local-FortiGate_root)

M

"firewallservicecategory'\SKIPPED,(name=General/oid=697,DUPLICATE)"

"firewalladdress",SUCCESS/(name=LOCAL_SUBNET,oid=684,newobject)',

"firewallservicecustom:SUCCESS,"(name=ALl,oid=863,updateprevious

object)*,

"firewallpolicy",SUCCESS,*(name=l,oid=1090,newobject)**

Giventheconfigurationshownintheexhibit,howdidFortiManagerhandIetheser

vicecategorynamedGeneraI?

AvFortiManagerignoredthefirewaIIservicecategoryGeneraIbutcreatedanew

servicecategoryinitsdatabase.

B、FortiManagerignoredthefirewaIIservicecategorygeneraIanddeIetedthed

upIicatevaIueInItsdatabase

C、FortiManagerignoredthefirewaIIservicecategoryGeneraIandupdatedtheF

ortiGatedupIicatevaIueintheFortiGatedatabase.

DvFortiManagerignoredthefirewaIIservicecategoryGeneraIanddidnotupdat

eItsdatabasewiththevaIue

答案:c

23.AnadministratorhasenabIedServiceAccessonFortiManager.

WhatisthepurposeofServiceAccessontheFortiManageriinterface?

AvAlIowsFortiManagertodownIoadIPSpackages

B、AlIowsFortiManagertorespondtorequestforFortiGuardservicesfromForti

Gatedevices

C、AlIowsFortiManagertorunreaI-timedebugsonthemanageddevices

DvAIIowsFortiManagertoautomaticaIIyconfigureadefauItroute

答案:B

24.ViewthefoIlowingexhibit,whichshowstheDownIoadImportReport:

Starttoimportconfigfromdevices(Remote-FortiGate)vdom(root)toadorn(MyADOM),

Package(Remote-FortiGate)

/

“firewalladdress”,SUCCESS/(name=REMOTE_SUBNET/oid=580/newobject)”

,//

“firewallpolicy/SUCCESS/(name=l/oid=990,newobject)”

“firewallpolicy",FAIL/(name=ID:2(#2),oid=991zreason=interface(interfacebinding

Contradiction.detail:any<-port6)bindingfaiir

WhyitisfaiIingtoimportfirewaIIpoIicyID2?

AvTheaddressobjectusedinpoIicyID2aIreadyexistinADONdatabasewithanyas

interfaceassociationandconfIictswithaddressobjectinterfaceassociation

IocaIIyontheFortiGate

B、PolicyID2isconfiguredfrominterfaceanytoport6FortiManagerrejectstoi

mportthispoIicybecauseanyinterfacedoesnotexistonFortiManager

C\PolicyID2doesnothaveAD0MInterfacemappingconfiguredonFortiManager

D、PoIicyID2forthismanagedFortiGateaIreadyexistsonFortiManagerinpoIic

ypackagenamedRemote-FortiGate.

答案:A

25.Anadministrator'sPCcrashesbeforetheadministratorcansubmitaworkfIo

wsessionforapprovaI.

AfterthePCisrestarted,theadministratornoticesthattheADOMwasIockedfrom

thesessionbeforethecrash.

HowcantheadministratorunIocktheADOM?

A、Restoretheconfigurationfromapreviousbackup.

B、LoginasSuper_UserinordertounIocktheADOM.

C、LoginusingthesameadministratoraccounttounIocktheADOM.

D、DeIetethepreviousadminsessionmanuaIIythroughtheFortiManagerGUIorCL

I.

答案:D

26.Refertotheexhibit.

SyscemlemptMes

iPsccTunnelIcnxMatct

SOWANTemoldtesPamaryDNSServer11

StMKRouteTcmpUte$OAAowOverrideQ

CertfftcateTemptotes

ScconctoryDNSServer192.168.1112

ThreatWeight

ClAlkr*Override0

CLITemptetes

LOCJIDomainN^me

N$X-TScfviceTem()Ufc

□AMOWOverrideO

■FrmwMVTc/ncMdies

AdvancedOptions>

AccordingtotheerrormessagewhyisFortiManagerfaiIingtoaddtheFortiAnaIyz

erdevice?

A、TheadministratormustturnoffthellseLegacyDeviceloginandaddtheFortiAn

aJyzerdevicetothesamenetworkasForti-Manager

B、TheadministratormustseIecttheForti-Manageradministrativeaccesschec

kboxontheFortiAnaIyzermanagementinterface

C、TheadministratormustusetheAddModeIDevicesectionanddiscovertheForti

AnaJyzerdevice

DvTheadministratormustusethecorrectusernameandpasswordoftheFortiAnaI

yzerdevice

答案:B

27.AnadministratorisintheprocessofmovingthesystemtempIateprofiIebetwe

enADOMsbyrunning

Thefollowingmand:

ExecuteimprofiIeimport-profiIeAD0M23547/tmp/myfiIe

WheredoestheadministratorimportthefiIefrom?

AxFiIesystem

B、AD0M1

GAD0M2objectdatabase

D、AD0M2

答案:D

28.AnadministratorrunthereIoadfaiIuremand:diagnosetestdepIoymanagerre

Ioadconfig

<deviceid>onFortiManager.

Whatdoesthismanddo?

AvItdownIoadstheIatestconfigurationfromthespecifiedFortiGateandperfo

rmsareIoadoperationonthedevicedatabase.

B、ItinstaIIstheIatestconfigurationonthespecifiedFortiGateandupdateth

erevisionhistorydatabase.

CvItparesandprovidesdifferencesinconfigurationonFortiManagerwiththec

urrentrunningconfigurationofthespecifiedFortiGate.

D、ItinstaIIstheprovisioningtempIateconfigurationonthespecifiedFortiG

ate.

答案:A

29.AnadministratorwiththeSuper_UserprofiIeisunabIetoIogintoFortiManag

erbecauseofan

AuthenticationfaiIuremessage.

WhichtroubIeshootingstepshouIdyoutaketoresoIvetheissue?

A、MakesureFortiManagerAccessisenabIedintheadministratorprofiIe

B\MakesureOffIineModeisdisabIed

C、MakesuretheadministratorIPaddressispartofthetrustedhosts.

D、MakesureADOMsareenabIedandtheadministratorhasaccesstotheGIobaIADOM

答案:c

30.AnadministratorhasassignedagIobaIpoIicypackagetoanewADOMcaIIedADOM

1.

WhatwiIIhappeniftheadministratortriestocreateanewpoIicypackageinADOM

1?

AvWhencreatinganewpoIicypackage,theadministratorcanseIecttheoptionto

assignthegIobaIpoIicypackagetothenewpoIicypackage

B、WhenanewpoIicypackageiscreated,theadministratorneedstoreappIythegI

obaIpoIicypackagetoADOMI.

C、WhenanewpoIicypackageiscreated,theadministratormustassignthegIobaI

poIicypackagefromthegIobaIADOM.

D、WhenthenewpoIicypackageiscreated,FortiManagerautomaticaIIyassignst

hegIobaIpoIicypackagetothenewpoIicypackage.

答案:D

31.ViewthefoIlowingexhibit.

Starttoimportconfigfromdevice(Local-FortiGate)vdom(root)toadomjMyADOM),package(Local-

Fortigateroot)

“firewallservicecategor/',SKIPPED,"(name二General,oid=697,DUPLICATE)**

“firewalladdress”,SUCCESS/r(name=LOCAL_SUBNET,oid=684,newobject)”

“firewallservicecustom”,SUCCESS,"(name二ALL,oid=863,updatepreviousobject)”

“firewallpolicy,/,SUCCESS//(name=l,oid-1090,newobject)**

WhichoneofthefoIIowingstatementsistrueregardingtheobjectnamedALL?

A、FortiManagerupdatedtheobjectALLusingFortiGate'svaIueinitsdatabase

B、FortiManagerupdatedtheobjectALLusingFortiManager'svaIueinitsdatab

ase

C、FortiManagercreatedtheobjectALLasauniqueentityinitsdatabase,whichc

anbeonIyusedbythismanagedFortiGate.

D、FortiManagerinstaIIedtheobjectALLwiththeupdatedvaIue.

答案:A

32.Refertotheexhibits.

Exhibitone.

DeviceManager▼Device&GroupsFirmwareLicenseProvisioningTemplatesScriptsSD-WA

MSaveiLInstallWizard

SNMP

SNMPAgentDEnable

SNMPvl/v2c

+CreateNew因Edit0View包Delete

Exhibittwo.

InstallPreview

VirtualDomain:global,root

configsystemntp

unsetntpsync

end

configsystememail-server

unsetserver

unsetsecurity

end

configlogfortianalyzersetting

unsetstatus

unsetserver

unsetupload-option

unsetreliable2

unsetserial

end

configsystemcentral-management

configserver-list

purge

end

end

configsystemglobal

unsetadmintimeout

unsetadmin*https*redirect

end

configsystemdns

setprimary1921681111

setsecondary1921681.112

end

configsystemsnmpsysinfo

AnadministratorcreatedanewsystemtempIatenamedTrainingwithtwonewDNSadd

resseson

FortiManager.DuringtheinstaIIationpreviewstage,theadministratornotice

sthatmanyunset

mandsneedtobepushed.

Whatcanbethemainreasonfortheseunsetmands?

A、TheDNSaddressesinthedefauItsystemsettingsarethesameastheTrainingsy

stemtempIate

B、TheTrainingsystemtempIatehasotherdefauItsettings

CvTheADOMisIockedbyanotheradministrator

D、TheTrainingsystemtempIatedoesnothaveassigneddevices

答案:B

33.Refertotheexhibit.

EditAddress

AddressName

LAN

Type

IP/Netmask

IP/Netmask

I192.168.1.O/255.255.255.O

Interface

anyx▼

StaticRouteConfiguration

OFF

Comments

AddtoGroups

AdvancedOptions〉

Per-DeviceMapping

+Add(3四I

NameVDOMDetails

□Remote-FortiGatcrootIP/Netmask:/255.255.255

AnadministratorhascreatedafirewaIIaddressobject,Trainingwhichisusedin

theLocaI-FortiGate

PoIicypackage.

WhentheinstaIIationoperationisperformed,whichIP/NetmaskwiIIbeinstaIIe

dontheLocaI-FortiGate,

FortheTrainingfirewaIIaddressobject?

A、192.168.0.1/24

Bx10.200.1.0/24

C、ItwiIIcreateafirewaIIaddressgrouponLocaI-FortiGatewith192.168.0.1/

24and10.0.1.0/24objectvaIues.

D、LocaI-FortiGatewiIIautomaticaIIychooseanIP/Netmaskbasedonitsnetwor

kinterfacesettings.

答案:B

34.IntheeventthattheprimaryFortiManagerfaiIs,whichofthefoIlowingactio

nsmustbeperformedto

ReturntheFortiManagerHAtoaworkingstate?

A、SecondarydevicewithhighestprioritywiIIautomaticaIIybepromotedtothe

primaryroIe,andmanuaIIyreconfigureaIIothersecondarydevicestopointtoth

enewprimarydevice

B、RebootoneofthesecondarydevicestopromoteitautomaticaIIytotheprimary

roIe,andreconfigureaIIothersecondarydevicestopointtothenewprimarydevi

C\ManuaIIypromoteoneofthesecondarydevicestotheprimaryroIe,andreconfi

gureaIIothersecondarydevicestopointtothenewprimarydevice.

D、FortiManagerHAstatetransitionistransparenttoadministratorsanddoesn

otrequireanyreconfiguration.

答案:c

35.WhatwiIIhappenifFortiAnaIyzerfeaturesareenabIedonFortiManager?

A、FortiManagerwiIIreboot

B、FortiManagerwiIIsendtheIoggingconfigurationtothemanageddevicessoth

emanageddeviceswiIIstartsendingIogstoFortiManager

C、FortiManagerwiIIenabIeADOMsautomaticaIIytocoIIectIogsfromnon-Forti

Gatedevices

DvFortiManagercanbeusedonIyasaIoggingdevice.

答案:A

36.ViewthefoIlowingexhibit.

Advanced

SNMP

MailServer

SyslogServer

MetaFieldsADOMModeONonnal

DeviceLogSettings

FileManagement

AdvancedSettings

Basedontheconfigurationsetting,whichoneofthefoIIowingstatementsistru

e?

AvThesettingenabIestheADOMsfeatureonFortiManager

B、ThesettingaIIowsautomaticupdatestothepoIicypackageconfigurationfor

amanageddevice

C\ThissettingaIIowsyoutoassigndifferentVDOMsfromthesameFortiGatetodi

fferentADOMs.

DvThesettingdisabIesconcurrentADOMaccessandaddsADOMIocking

答案:c

37.WhatwiIIhappenifFortiAnaIyzerfeaturesareenabIedonFortiManager?

A、FortiManagerwiIIkeepalItheIogsandreportsontheFortiManager.

B、FortiManagerwiIIenabIeADOMstocoIIectIogsautomaticaIIyfromnon-Forti

Gatedevices.

C\FortiManagerwiIIinstaIItheIoggingconfigurationtothemanageddevices

D、FortiManagercanbeusedonIyasaIoggingdevice.

答案:c

38.Refertotheexhibit.

configsystemdm

setrollback-allow-rebootenable

end

AnadministratorhasconfiguredthemandshownintheexhibitonFortiManager.Ac

onfiguration

ChangehasbeeninstaIIedfromFortiManagertothemanagedFortiGatethatcauses

theFGFMtunneIto

Godownformorethanl5minutes.

Whatisthepurposeofthismand?

A、ItaIIowsFortiGatetounsetcentraImanagementsettings.

B、ItaIIowsFortiGatetorebootandrecoverthepreviousconfigurationfromits

configurationfiIe.

C、ItaIIowstheFortiManagertorevertandinstaIIapreviousconfigurationrev

isiononthemanagedFortiGate.

D、ItaIIowsFortiGatetorebootandrestoreapreviousIyworkingfirmwareimage.

答案:B

39.AsaresuItofenabIingFortiAnaIyzerfeaturesonFortiManager,whichofthef

oIIowingstatementsistrue?

A、FortiManagerwiIIenabIeADOMsautomaticaIIytocoIIectIogsfromnon-Forti

Gatedevices

B、FortiManagerwiIIsendtheIoggingconfigurationtothemanageddevicessoth

emanageddeviceswiIIstartsendingIogstoFortiManager

C、FortiManagerwiIIreboot

D、FortiManagercanbeusedonIyasaIoggingdevice.

答案:c

40.AnadministratorisrepIacingadeviceonFortiManagerbyrunningthefoIlowi

ngmand:

ExecutedevicerepIacesn<devname><seriaInum>.

WhatdevicenameandseriaInumbermusttheadministratoruse?

A、DevicenameandseriaInumberoftheoriginaIdevice.

B、DevicenameandseriaInumberoftherepIacementdevice.

C、DevicenameoftherepIacementdeviceandseriaInumberoftheoriginaIdevice.

DvDevicenameoftheor

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论