Proper study guides for NSE8 NSE8 certified begins with preparation products which designed to deliver the by making you pass the NSE8 test at your first time. Try the free right now.
Free demo questions for Fortinet NSE8 Exam Dumps Below:
NEW QUESTION 1
A customer has the following requirements:
- local peer with two Internet links
- remote peer with one Internet link
- secure traffic between the two peers
- granular control with Accept policies
Which solution provides security and redundancy for traffic between the two peers?
- A. a fully redundant VPN with interface mode configuration
- B. a partially redundant VPN with interface mode configuration
- C. a partially redundant VPN with tunnel mode configuration
- D. a fully redundant VPN with tunnel mode configuration
Answer: B
NEW QUESTION 2
You notice that your FortiGate’s memory usage is very high and that the unit’s performance is adversely affected. You want to reduce memory usage.
Which three commands would meet this requirement? (Choose three.)
- A.

- B.

- C.

- D.

- E.

Answer: ADE
NEW QUESTION 3
Which command detects where a routing path is broken?
- A. exec traceroute <destination>
- B. exec route ping <destination>
- C. diag route null
- D. diag debug route <destination>
Answer: A
NEW QUESTION 4
The output shown in the exhibit from FortiManager is displayed during an import of the device configuration.
Which statement describes the correct action taken for these duplicate objects?
- A. The import fails because of the duplicate entries detected which exist in the ADOM database.
- B. FortiManager installs these duplicate objects to the managed device from the ADOM database.
- C. FortiManager does not import these duplicate entries into the ADOM database because they already exist in the ADOM database.
- D. FortiManager creates indexed duplicate entries for these objects in the ADOM database.
Answer: B
Explanation: References:
http://docs.fortinet.com/uploaded/files/2905/FortiManager-5.4.0-Administration-Guide.pdf
NEW QUESTION 5
A café offers free Wi-Fi. Customers’ portable electronic devices often do not have antivirus software installed and may be hosting worms without their knowledge. You must protect all customers from any other customers’ infected devices that join the same SSID.
Which step meets the requirement?
- A. Enable deep SSH inspection with antivirus and IPS.
- B. Use a captive portal to redirect unsecured connections such as HTTP and SMTP to their secured equivalents, preventing worms on infected clients from tampering with other customer traffic.
- C. Use WPA2 encryption and configure a policy on FortiGate to block all traffic between clients.
- D. Use WPA2 encryption, and enable “Block Intra-SSID Traffic”.
Answer: B
NEW QUESTION 6
You want to enable traffic between 2001:db8:1::/64 and 2001:db8:2::/64 over the public IPv4 Internet.
Given the CLI configuration shown in the exhibit, which two additional settings are required on this device to implement tunneling for the IPv6 transition? (Choose two.)
- A. IPv4 firewall policies to allow traffic between the local and remote IPv6 subnets.
- B. IPv6 static route to the destination phase2 destination subnet.
- C. IPv4 static route to the destination phase2 destination subnet.
- D. IPv6 firewall policies to allow traffic between the local and remote IPv6 subnets.
Answer: BD
Explanation: References: http://docs.fortinet.com/uploaded/files/1969/IPv6%20Handbook%20for%20FortiOS%205.2. pdf
NEW QUESTION 7
A university is looking for a solution with the following requirements:
- wired and wireless connectivity
- authentication (LDAP)
- Web filtering, DLP and application control
- data base integration using LDAP to provide access to those students who are up-to-date with their monthly payments
- support for an external captive portal Which solution meets these requirements?
- A. FortiGate for wireless controller and captive portalFortiAP for wireless connectivityFortiAuthenticator for user authentication and REST API for DB integrationFortiSwitch for PoE connectivityFortiAnalyzer for log and report
- B. FortiGate for wireless controllerFortiAP for wireless connectivityFortiAuthenticator for user authentication, captive portal and REST API for DB integrationFortiSwitch for PoE connectivityFortiAnalyzer for log and report
- C. FortiGate for wireless control and user authenticationFortiAuthenticator for captive portal and REST API for DB integrationFortiAP for wireless connectivityFortiSwitch for PoE connectivityFortiAnalyzer for log and report
- D. FortiGate for wireless controllerFortiAP for wireless connectivity and captive portalFortiSwitch for PoE connectivityFortiAuthenticator for user authentication and REST API for DB integrationFortiAnalyzer for log and reports
Answer: A
NEW QUESTION 8
Your colleague has enabled virtual clustering to load balance traffic between the cluster units. You notice that all traffic is currently directed to a single FortiGate unit. Your colleague has applied the configuration shown in the exhibit.
Which step would you perform to load balance traffic within the virtual cluster?
- A. Issue the diagnose sys ha reset-uptime command on the unit that is currently processing traffic to enable load balancing.
- B. Add an additional virtual cluster high-availability link to enable cluster load balancing.
- C. Input Virtual Cluster domain 1 and Virtual Cluster domain 2 device priorities for each cluster unit.
- D. Use the set override enable command on both units to allow the secondary unit to load balance traffic.
Answer: C
Explanation: References:
NEW QUESTION 9
Which command syntax would you use to configure the serial number of a FortiGate as its host name?
- A.

- B.

- C.

- D.

Answer: AB
Explanation: References:
http://defadhil.blogspot.in/2014/04/how-to- protect-fortigate- from.html
NEW QUESTION 10
An administrator wants to assign static IP addresses to users connecting tunnel-mode SSL VPN. Each SSL VPN user must always get the same unique IP address which is never assigned to any other user.
Which solution accomplishes this task?
- A. TACACS+ authentication with an attribute-value (AV) pair containing each user’s IP address.
- B. RADIUS authentication with each user’s IP address stored in a Vendor Specific Attribute (VSA).
- C. LDAP authentication with an LDAP attribute containing each user’s IP address.
- D. FSSO authentication with an LDAP attribute containing each user’s IP address.
Answer: D
NEW QUESTION 11
FortiGate1 has a gateway-to-gateway IPsec VPN to FortiGate2. The entire IKE negotiation between FortiGate1 and FortiGate2 is on UDP port 500. A PC on FortuGate2’s local area network is sending continuous ping requests over the VPN tunnel to a PC of FortiGate1’s local area network. No other traffic is sent over the tunnel.
Which statement is true on this scenario?
- A. FortiGate1 sends an R-U-THERE packet every 300 seconds while ping traffic is flowing.
- B. FortiGate1 sends an R-U-THERE packet if pings stop for 300 seconds and no IKE packet is received during this period.
- C. FortiGate1 sends an R-U-THERE packet if pings stop for 60 seconds and no IKE packet is received during this period.
- D. FortiGate1 sends an R-U-THERE packet every 60 seconds while ping traffic is flowing.
Answer: C
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=FD35337
NEW QUESTION 12
The FortiGate is an IPsec VPN hub. A VPN spoke protecting subnet 192.168.222.0/24 has successfully brought up a tunnel with the FortiGate. This remote network is present in the FortiGate routing table as shown in the exhibit.
Which statement is true?
- A. This subnet was learned during quick-mode negotiation and was dynamically injected into the routing table.
- B. The FortiGate administrator configured this subnet as a locally connected subnet on the “BranchOffice” phase1 interface.
- C. The route in the exhibit is bound to “BranchOffice_0” which is a tunnel other than “BranchOffice”.
- D. The FortiGate administrator configured a static route for 192.168.222.0/24.
Answer: B
NEW QUESTION 13
Virtual Domains (VDOMs) allow a FortiGate administrator to do what?
- A. Group two or more FortiGate units to form a single virtual device.
- B. Split a physical FortiGate unit into multiple virtual devices.
- C. Create multiple VLANs in a single physical interface,
- D. Group multiple physical interfaces to form a single virtual interface.
Answer: B
NEW QUESTION 14
You are managing a FortiAnalyzer appliance. After an upgrade, you notice that the unit no longer displays historical logs, reports do not produce any data, and FortiView summary views are empty. However, you notice that the unit is receiving logs on the dashboard widgets.
Which step resolves this problem?
- A. Execute the CLI command exec sql-local rebuild-db.
- B. Execute the CLI command diag sql remove hcache.
- C. Execute the CLI command exec sql-local reinsert-logs.
- D. Restore the unit settings from a previous backup.
Answer: A
NEW QUESTION 15
Referring to the exhibit, you want to know if aggregating port7 and port22 will work. Which statement is correct?
- A. Yes, LACP is supported on all ports regardless if they are connected to the same NP6.
- B. No, LACP is not supported on NP6 platforms.
- C. No, LACP is only supported on ports connected to the same NP6.
- D. Yes, LACP is supported on ports that are linked together with integrated Switch Fabric.
Answer: C
Explanation: References:
http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-hardware-acceleration- 52/NP6.htm
NEW QUESTION 16
Your FortiGate has multiple CPUs. You want to verify the load for each CPU. Which two commands will accomplish this task? (Choose two.)
- A. get system performance status
- B. diag system mpstat
- C. diag system cpu stat
- D. diag system top
Answer: AD
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=13825
NEW QUESTION 17
Which three statements about throughput on a wireless network are true? (Choose three.)
- A. A wireless device labelled as 300 Mbps should be expected to provide a throughput of 300Mbps.
- B. Be careful to ensure the capabilities of the wireless clients match those of the access points, in order to achieve higher throughput.
- C. Reducing the duty cycles of the wireless media by generating fewer beacons may improve throughput.
- D. Because of the higher level of RF noise that is typical in the 2.4 GHz ISM band, throughput of 2.4 GHz devices will typically be less than 5 GHz devices.
- E. Because of the full-duplex nature of the medium and the minimal overhead generated by CSMA/CA, the actual aggregate throughput is typically close to the data rate.
Answer: BCD
Explanation: References:
http://www.tp-link.in/faq-499.html
P.S. Simply pass now are offering 100% pass ensure NSE8 dumps! All NSE8 exam questions have been updated with correct answers: https://www.simply-pass.com/Fortinet-exam/NSE8-dumps.html (65 New Questions)