Free NSE8-812 Fortinet NSE8-812 Practice Test Question

Loading demo links...

Showing 4–6 of 10 questions

Question 4 (Topic 1)

You are migrating the branches of a customer to FortiGate devices. They require independent routing tables on the LAN side of the network. After reviewing the design, you notice the firewall will have many BGP sessions as you have two data centers (DC) and two ISPs per DC while each branch is using at least 10 internal segments. Based on this scenario, what would you suggest as the more efficient solution, considering that in the future the number of internal segments, DCs or internet links per DC will increase?

Select an option, then click Submit answer.

  • No change in design is needed as even small FortiGate devices have a large memory capacity
  • Acquire a FortiGate model with more capacity, considering the next 5 years growth
  • Implement network-id, neighbor-group and increase the advertisement-interval
  • Redesign the SD-WAN deployment to only use a single VPN tunnel and segment traffic using VRFs on BGP
Question 5 (Topic 1)

Refer to the exhibit. A customer wants FortiClient EMS configured to deploy to 1500 endpoints The deployment will be integrated with FortiOS and there is an Active Directory server. Given the configuration shown in the exhibit, which two statements about the installation are correct? (Choose two.)

Select an option, then click Submit answer.

  • If no client update time is specified on EMS, the user will be able to choose the time of installation if they wish to delay.
  • A client can be eligible for multiple enabled configurations on the EMS server, and one will be chosen based on first priority.
  • You can only deploy initial installations to Windows clients.
  • You must use Standard or Enterprise SQL Server rather than the included SQL Server Express.
  • The Windows clients only require “File and Printer Sharing” allowed and the rest is handled by Active Directory group policy.
Question 6 (Topic 1)

You have configured a Site-to-Site IPsec VPN tunnel between a FortiGate and a third-party device but notice that one of the error counters on the tunnel interface keeps increasing. Which two configuration options can resolve this problem? (Choose two.)

Select an option, then click Submit answer.

  • Enable Forward Error Correction (FEC) on the VPN interface for egress traffic.
  • Enable DF-bit honoring in the global settings.
  • Adjust the MTU of the physical interface to which the IPsec tunnel is bound.
  • Adjust the MTU of the IPsec interface.