Proper study guides for NSE8 NSE8 certified begins with preparation products which designed to deliver the by making you pass the NSE8 test at your first time. Try the free right now.
Check NSE8 free dumps before getting the full version:
NEW QUESTION 1
You implemented FortiGate in transparent mode with 10 different VLAN interfaces in the same forwarding domain. You have defined a policy to allow traffic from any interface to any interface.
Which statement about your implementation is true?
- A. FortiGate populates the MAC address table based on destination addresses of frames received from all 10 VLANs.
- B. There will be no impact on the STP protocol.
- C. All 10 VLANs will become a single broadcast domain for the ARP request.
- D. The ARP request will not be forwarded across the different VLANs domains.
Answer: C
Explanation: References: http://kb.fortinet.com/kb/viewAttachment.do?attachID=Fortigate_Transparent_Mode_Techn ical_Guide_FortiOS_4_0_version1.2.pdf&documentID=FD33113
NEW QUESTION 2
A customer is authenticating users using a FortiGate and an external LDAP server. The LDAP user, John Smith, cannot authenticate. The administrator runs the debug command diagnose debug application fnbamd 255 while John Smith attempts the authentication:
Based on the output shown in the exhibit, what is causing the problem?
- A. The LDAP administrator password in the FortiGate configuration is incorrect.
- B. The user, John Smith, does have an account in the LDAP server.
- C. The user, John Smith, does not belong to any allowed user group.
- D. The user, John Smith, is using an incorrect password.
Answer: A
Explanation: Fortigate not binded with LDAP server because of failed authentication. References:
NEW QUESTION 3
There is an interface-mode IPsec tunnel configured between FortiGate1 and FortiGate2. You want to run OSPF over the IPsec tunnel. On both FortiGates. the IPsec tunnel is based on physical interface port1. Port1 has the default MTU setting on both FortiGate units.
Which statement is true about this scenario?
- A. A multicast firewall policy must be added on FortiGate1 and FortiGate2 to allow protocol 89.
- B. The MTU must be set manually in the OSPF interface configuration.
- C. The MTU must be set manually on the IPsec interface.
- D. An IP address must be assigned to the IPsec interface on FortiGate1 and FortiGate2.
Answer: B
Explanation: If MTU doesn’t match then the neighbour ship gets stuck in exchange state.
NEW QUESTION 4
You have received an issue report about users not being able to use a video conferencing application. This application uses two UDP ports and two TCP ports to communicate with servers on the Internet. The network engineering team has confirmed there is no routing problem. You are given a copy of the FortiGate configuration.
Which three configuration objects will you inspect to ensure that no policy is blocking this traffic? (Choose three.)
- A. config firewall interface-policy
- B. config firewall DoS-policy
- C. config firewall policy
- D. config firewall multicast-policy
- E. config firewall sniffer-policy
Answer: BCE
NEW QUESTION 5
A company wants to protect against Denial of Service attacks and has launched a new project. They want to block the attacks that go above a certain threshold and for some others they are just trying to get a baseline of activity for those types of attacks so they are
letting the traffic pass through without action. Given the following:
- The interface to the Internet is on WAN1.
- There is no requirement to specify which addresses are being protected or protected from.
- The protection is to extend to all services.
- The tcp_syn_flood attacks are to be recorded and blocked.
- The udp_flood attacks are to be recorded but not blocked.
- The tcp_syn_flood attack’s threshold is to be changed from the default to 1000. The exhibit shows the current DoS-policy.
Which policy will implement the project requirements?
- A.

- B.

- C.

- D.

Answer: BD
Explanation: B&D both have same policy which fulfills the above criteria. http://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-firewall-52/Examples/Example-%20DoS%20Policy.htm
NEW QUESTION 6
Given the following error message:
FortiManager fails to import policy ID 1. What is the problem?
- A. FortiManager already has Address LAN which has interface mapping set to “internal” in its database, it is contradicting with the STUDENT-2 FortiGate device which has address LAN mapped to “any”.
- B. FortiManager already has address LAN which has interface mapping set to “any” in its database; this conflicts with the STUDENT-2 FortiGate device which has address “LAN”mapped to “internal”.
- C. Policy ID 1 for this managed FortiGate device already exists on the FortiManager policy package named STUDENT-2.
- D. Policy ID 1 does not have interface mapping on FortiManager.
Answer: D
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=FD38544
NEW QUESTION 7
You have replaced an explicit proxy Web filter with a FortiGate. The human resources department requires that all URLs be logged. Users are reporting that their browsers are now indicating certificate errors as shown in the exhibit.
Which step is a valid solution to the problem?
- A. Make sure that the affected users’ browsers are no longer set to use the explicit proxy.
- B. Import the FortiGate’s SSL CA certificate into the Web browsers.
- C. Change the Web filter policies on the FortiGate to only do certificate inspection.
- D. Make a Group Policy to install the FortiGate’s SSL certificate as a trusted host certificate on the Web browser.
Answer: D
Explanation: For https traffic inspection, client machine should install fortigate’s ssl certificate
NEW QUESTION 8
A company has just installed a new FortiGate in their core to route and inspect traffic between their subnetted VLANs. The security department reports that after the installation, their IP video cameras no longer work. Research by the IT department shows that the video system uses a multicast stream to send the video to multiple video receivers.
Which two commands must be configured to resolve this problem? (Choose two.)
- A.

- B.

- C.

- D.

Answer: BD
Explanation: http://kb.fortinet.com/kb/documentLink.do?externalID=FD36500
NEW QUESTION 9
The dashboard widget indicates that FortiGuard Web Filtering is not reachable. However, AntiVirus, IPS, and Application Control have no problems as shown in the exhibit.
You contacted Fortinet’s customer service and discovered that your FortiGuard Web Filtering contract is still valid for several months.
What are two reasons for this problem? (Choose two.)
- A. You have another security device in front of FortiGate blocking ports 8888 and 53.
- B. FortiGuard Web Filtering is not enabled in any firewall policy.
- C. You did not enable Web Filtering cache under Web Filtering and E-mail Filtering Options.
- D. You have a firewall policy blocking ports 8888 and 53.
Answer: BD
Explanation: If Web filtering shows unreachable then we have to verify, whether web filtering enabled in security policies or not.
Web filtering enabled in a policy but the port 8888 and 53 are not selected, means the policy blocking the ports.
References:
NEW QUESTION 10
A customer just bought an additional FortiGate device and plans to use their existing load balancer to distribute traffic across two FortiGate units participating on a BGP network serving different neighbors. The customer has mixed traffic of IPv4 and IPv6 TCP, UDP, and ICMP. The two FortiGate devices shown in the exhibit should be redundant to each other so that the NAT session and active session tables will synchronize and fail over to the unit that is still operating without any loss of data if one of the units fail.
Which high availability solution would you implement?
- A. FortiGate Cluster Protocol (FGCP)
- B. Fortinet redundant UTM protocol (FRUP)
- C. FortiGate Session Life Support Protocol (FGSP)
- D. Virtual Router Redundancy Protocol (VRRP)
Answer: A
Explanation: References:
http://docs.fortinet.com/uploaded/files/1074/fortigate-ha-40-mr2.pdf
NEW QUESTION 11
You are asked to write a FortiAnalyzer report that lists the session that has consumed the most bandwidth. You are required to include the source IP, destination IP, application, application category, hostname, and total bandwidth consumed.
Which dataset meets these requirements?
- A. select from_itime(itime) as timestamp, srcip, dstip, app, appcat, hostname, sum(coalesce(‘sentbyte”, 0) +coalesce(‘recbyte “, 0)) as bandwidth from $log where $filter LIMIT 1
- B. select from_itime(itime) as timestamp, srcip, dstip, app, appcat, hostname, sum(coalesce(‘sentbyte”, 0) +coalesce(‘recbyte“, 0)) as bandwidth from $log where $filter LIMIT 1
- C. select from_itime(itime) as timestamp, srcip, dstip, app, appcat, hostname, sum(coalesce(‘sentbyte”, 0) +coalesce(‘rcvdbyte“, 0)) as bandwidth from $log where $filter LIMIT 1
- D. select from_itime(itime) as timestamp, sourceip, destip, app, appcat, hostname, sum(coalesce(‘sentbyte’, 0)+coalesce(‘rcvdbyte“, 0)) as bandwidth from $log where $filter LIMIT 1
Answer: C
Explanation: References:
http://docs.fortinet.com/uploaded/files/2617/fortianalyzer-5.2.4-dataset-reference.pdf
NEW QUESTION 12
Which three configuration scenarios will result in an IPsec negotiation failure between two FortiGate devices? (Choose three.)
- A. mismatched phase 2 selectors
- B. mismatched Anti-Replay configuration
- C. mismatched Perfect Forward Secrecy
- D. failed Dead Peer Detection negotiation
- E. mismatched IKE version
Answer: ACE
Explanation: In IPsec negotiations, Perfect Forward Secrecy (PFS) ensures that each new cryptographic key is unrelated to any previous key. Either enable or disable PFS on both the tunnel peers; otherwise, the LAN-to-LAN (L2L) IPsec tunnel is not established
NEW QUESTION 13
Your security department has requested that you implement the OpenSSL.TLS.Heartbeat.Information.Disclosure signature using an IPS sensor to scan traffic destined to the FortiGate. You must log all packets that attempt to exploit this vulnerability.
Referring to the exhibit, which two configurations are required to accomplish this task? (Choose two.)
- A.

- B.

- C.

- D.

Answer: B
Explanation: http://defadhil.blogspot.in/2014/04/how-to-protect-fortigate-from.html
NEW QUESTION 14
The exhibit shows an explicit Web proxy configuration in a FortiGate device. The FortiGate is installed between a client with the IP address 172.16.10.4 and a Web server using port 80 with the IP address 10.10.3.4. The client Web browser is properly sending HTTP traffic to the FortiGate Web proxy IP address 172.16.10.254.
Which two sniffer commands will capture this HTTP traffic? (Choose two.)
- A. diagnose sniffer packet any ‘host 172.16.10.4 and host 172.16.10.254’ 3
- B. diagnose sniffer packet any ‘host 172.16.10.254 and host 10.10.3.4’ 3
- C. diagnose sniffer packet any ‘host 172.16.10.4 and port 8080’ 3
- D. diagnose sniffer packet any ‘host 172.16.10.4 and host 10.10.3.4’ 3
Answer: CD
Explanation: Sniffer should run between webproxy to webserver
And also Sniffer between client machine to web proxy connectivity as it is in explicit mode.
References:
NEW QUESTION 15
Referring to the configuration shown in the exhibit, which three statements are true? (Choose three.)
- A. Traffic logging is disabled in policy 96.
- B. TCP handshake is completed and no FIN/RST has been forwarded.
- C. No packet has hit this session in the last five minutes.
- D. No QoS is applied to this traffic.
- E. The traffic goes through a VIP applied to policy 96.
Answer: BCE
Explanation: References:
http://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
NEW QUESTION 16
You are asked to establish a VPN tunnel with a service provider using a third-party VPN device. The service provider has assigned subnet 30.30.30.0/24 for your outgoing traffic going towards the services hosted by the provider on network 20.20.20.0/24. You have multiple computers which will be accessing the remote services hosted by the service provider.
Which three configuration components meet these requirements? (Choose three.)
- A. Configure an IP Pool of type Overload for range 30.30.30.10-30.30.30.10. Enable NAT on a policy from your LAN forwards the VPN tunnel and select that pool.
- B. Configure IPsec phase 2 proxy IDs for a source of 10.10.10.0/24 and destination of 20.20.20.0/24.
- C. Configure an IP Pool of Type One-to-One for range 30.30.30.10-30.30.30.10. Enable NAT on a policy from your LAN towards the VPN tunnel and select that pool.
- D. Configure a static route towards the VPN tunnel for 20.20.20.0/24.
- E. Configure IPsec phase 2 proxy IDs for a source of 30.30.30.0/24 and destination of 20.20.20.0/24.
Answer: CDE
NEW QUESTION 17
Given the following FortiOS 5.2 commands:
Which vulnerability is being addresses when managing FortiGate through an encrypted management protocol?
- A. Remote Exploit Vulnerability in Bash (ShellShock)
- B. Information Disclosure Vulnerability in OpenSSL (Heartbleed)
- C. SSL v3 POODLE Vulnerability
- D. SSL/TLS MITM vulnerability (CVE-2014-0224)
Answer: C
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=FD36913
P.S. prep-labs.com now are offering 100% pass ensure NSE8 dumps! All NSE8 exam questions have been updated with correct answers: https://www.prep-labs.com/dumps/NSE8/ (65 New Questions)