NSE8_811 Fortinet NSE 8 Written Exam

Loading demo links...

Showing 7–9 of 10 questions

Question 7

You configured a firewall policy with only a Web filter profile for accessing the Internet. Access to websites belonging to the "Information Technology" category are blocked and to the "Business" category are allowed. SSL deep inspection is not enabled on this policy.

A user wants to access the website https://www.it-acme.com which presents a certificate with CN=www.acme.com. The it-acme.com domain is categorized as "Information Technology" and the acme.com domain is categorized as "Business".

Which statement regarding this scenario is correct?

Select an option, then click Submit answer.

  • The FortiGate is able to read the URL within HTTPS sessions when using SSL certificate inspection so the website will be blocked by the "Information Technology".

  • The website will be blocked by category "Information Technology" as the SNI takes precedence over the certificate name.

  • The website will be allowed by category "Business" as the certificate name takes precedence over the URL.

  • Only with SSL deep inspection enabled will the FortiGate be able to categorized this website.

Question 8

Refer to the exhibit.

The exhibit shows the steps for creating a URL rewrite policy on a FortiWeb.

Which statement represents the purpose of this policy?

Select an option, then click Submit answer.

  • The policy redirects all HTTPS URLs to HTTP.

  • The policy redirects all HTTP URLs to HTTPS.

  • The policy redirects only HTTP URLs containing the ^/(.*)$ string to HTTPS.

  • The policy redirects only HTTPS URLs containing the ^/(.*)$ string to HTTP.

Question 9

Refer to the exhibit.

As shown in the exhibit, a FortiADC is load-balancing IPv4 traffic between two next-hop routers. The FortiADC does not know the IP addresses of the servers. Also, the FortiADC is doing Layer 7 content inspection and modification.

In this scenario, which application delivery control is configured in the FortiADC?

Select an option, then click Submit answer.

  • Layer 3

  • Layer 4

  • Layer 7

  • Layer 2