Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Fortinet NSE 8 - Written Exam NSE8_812 Exam Questions

Page: 1 / 11 Total 105 questions

Want more questions? Get Premium Access.

Question 1

Refer to the exhibits.

To facilitate a more efficient roll out of FortiGate devices, you are tasked with using meta fields with the CLI Template to configure the DHCP server on the "office1" FortiGate.

Given this scenario, what would be the output of the config ip-range section on the CLI Template?

A.

B.

C.

D.

Correct Answer: A. Option A

Question 3

Which two statements about bounce address tagging and verification (BATV) on FortiMail are true? (Choose two.)

Correct Answer: B. Emails with an empty sender address will be subjected to bounce verification.; C. FortiMail will insert the BATV tag to the sender address in the envelope.

Question 4

Refer to the exhibits, which show a topology and diagnostic commands.

Which two statements about the path resolution are true? (Choose two.)

Correct Answer: A. Latency is the quality criteria.

Question 5

A FortiGate is configured to perform outbound firewall authentication with Azure AD as a SAML IdP.

What are two valid interactions that occur when the client attempts to access the internet? (Choose two.)

Correct Answer: A. FortiGate SP sends a SAML request to the IdP.; B. The Microsoft SAML IdP sends the SAML response to the FortiGate SP.

Question 7

Refer to the exhibits.

You must integrate a FortiMail and FortiSandbox Enhanced Cloud solution for a customer who is concerned about the e-mails being delayed for too long.

According to the configuration shown in the exhibits, which would be an expected behavior?

Correct Answer: A. FortiMail will relay valid e-mails to the mail server as soon as it is done with other local inspections.

Question 8

An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the OCSP server.

Part of the FortiGate configuration is shown below:

Based on this configuration, which authentication scenario will FortiGate deny?

Correct Answer: B. FortiAuthenticator responds to an OCSP request that the user certificate authority is untrusted.

Question 9

Refer to the exhibit.

You are managing a FortiSwitch 3032E that is managed by FortiLink on a FortiGate 3960E. The 3032E is heavily utilized and there is only one port free.

The requirement is to add an additional three FortiSwitch 448E devices with 10Gbps SFP+ connectivity directly to the 3032E. The plan is to use split port (phy-mode) with QSFP28 mode to connect the new 448E switches.

In this scenario, which statement about the switch deployment is correct?

Correct Answer: B. The port most of Switch 1 must be changed to QSFP.

Question 10

You are responsible for recommending an adapter type for NICs on a FortiGate VM that will run on an ESXi Hypervisor. Your recommendation must consider performance as the main concern, cost is not a factor. Which adapter type for the NICs will you recommend?

Correct Answer: D. Physical Function (PF) PCI Passthrough