Yeah, I think B makes the most sense here. Application control taps right into IPS protocol decoders and signatures, that's its main role for blocking various app traffic types at the firewall level. The other options are more about web or DNS filtering, not actual deep app inspection. If I'm missing something, let me know!
Q: 11
What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on
network transmission patterns and application signatures?
Options
Discussion
Its B. Practice tests and Fortinet docs cover how application control uses signatures and protocol decoders for this. Seen similar on exams.
Probably B. Application control is the only one here that uses IPS protocol decoders and signatures to block or allow app traffic, not just web filtering or DNS. The rest seem off for deep inspection cases.
C/D? Not convinced it's C, since SD-WAN rules don't use IPS protocol decoders that way. D might look tempting but web filter doesn't handle all protocols. Pretty sure B fits closer to what exam reports say: application control uses those signatures. Anyone disagree?
Be respectful. No spam.
Q: 12
Refer to the exhibit, which contains the partial output of an OSPF command.
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in
the exhibit.
What two conclusions can the administrator draw? (Choose two.)
An administrator is checking the OSPF status of a FortiGate device and receives the output shown in
the exhibit.
What two conclusions can the administrator draw? (Choose two.)Options
Discussion
B C tbh. Had something like this in a mock, matches the "area border router" and "ASBR" lines.
Definitely B and C. The output says it's an area border router (so multiple areas) and also shows it's an ASBR, which means it injects external routes. Pretty sure on these, but let me know if you see something I missed.
Be respectful. No spam.
Q: 13
Why does the ISDB block layers 3 and 4 of the OSI model when applying content filtering? (Choose
two.)
Options
Discussion
A vs B-I think both are right here. ISDB uses FortiGuard to pull predefined IPs and ports (layers 3 and 4) for blocking, not URLs or proxy mode. Not 100% but that's what I've seen in docs.
Official guide and practice exam questions both say ISDB works by blocking IPs and ports from FortiGuard, so I'd focus study on those docs for anything OSI layer 3/4 related.
A and B tbh. I remember from a practice test that ISDB lets FortiGate block based on the IPs and ports tied to certain apps, which is layers 3 and 4 stuff. Pretty sure it isn’t proxying or using URLs for this. Someone else seen this work differently?
Be respectful. No spam.
Q: 14
Refer to the exhibit, which shows an enterprise network connected to an internet service provider.
An administrator must configure a loopback as a BGP source to connect to the ISP.
Which two commands are required to establish the connection? (Choose two.)
An administrator must configure a loopback as a BGP source to connect to the ISP.
Which two commands are required to establish the connection? (Choose two.)Options
Discussion
Its A and B. Both needed when you set up BGP neighbors via loopback so the session can come up.
Probably A and B. You need
ebgp-enforce-multihop or else the session drops due to TTL if using loopbacks, and update-source tells BGP to use the loopback IP as its source. Pretty standard for eBGP over loopback, right?A and B imo, saw similar question in some practice tests. Using loopback as BGP source needs both.
Be respectful. No spam.
Q: 15
Refer to the exhibit, which shows a LAN interface connected from FortiGate to two FortiSwitch
devices.
What two conclusions can you draw from the corresponding LAN interface? (Choose two.)
What two conclusions can you draw from the corresponding LAN interface? (Choose two.)Options
Discussion
B/C make sense here. The interface needs to be 802.3ad (B) for aggregation and FortiLink is used to centrally manage VLANs (C). Not seeing any SD-WAN or STP requirement in this context. Anyone disagree?
Pretty sure it's B and C, saw a similar question on a practice exam. Matches the 802.3ad and FortiLink setup.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2