We provide which are the best for clearing NSE8 test, and to get certified by Fortinet NSE8. The covers all the knowledge points of the real NSE8 exam. Crack your Fortinet NSE8 Exam with latest dumps, guaranteed!

Online Fortinet NSE8 free dumps demo Below:

NEW QUESTION 1
You are installing a new FortiAP as shown in the exhibit, however, the FortiAP cannot discover the FortiGate. The FortiAP obtained an IP from the DHCP server and is reachable.
NSE8 dumps exhibit
Which two configurations will resolve the problem? (Choose two.)

  • A. NSE8 dumps exhibit
  • B. NSE8 dumps exhibit
  • C. NSE8 dumps exhibit
  • D. NSE8 dumps exhibit

Answer: BD

Explanation: https://forum.fortinet.com/tm.aspx?m=112739

NEW QUESTION 2
A company wants to protect against Denial of Service attacks and has launched a new project. They want to block the attacks that go above a certain threshold and for some others they are just trying to get a baseline of activity for those types of attacks so they are
letting the traffic pass through without action. Given the following:
- The interface to the Internet is on WAN1.
- There is no requirement to specify which addresses are being protected or protected from.
- The protection is to extend to all services.
- The tcp_syn_flood attacks are to be recorded and blocked.
- The udp_flood attacks are to be recorded but not blocked.
- The tcp_syn_flood attack’s threshold is to be changed from the default to 1000. The exhibit shows the current DoS-policy.
NSE8 dumps exhibit
Which policy will implement the project requirements?

  • A. NSE8 dumps exhibit
  • B. NSE8 dumps exhibit
  • C. NSE8 dumps exhibit
  • D. NSE8 dumps exhibit

Answer: BD

Explanation: B&D both have same policy which fulfills the above criteria. http://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-firewall-52/Examples/Example-%20DoS%20Policy.htm

NEW QUESTION 3
Which Fortinet product is used for antispam protection?

  • A. FortiSwitch
  • B. FortiGate
  • C. FortiWeb
  • D. FortiDB

Answer: B

NEW QUESTION 4
A customer just bought an additional FortiGate device and plans to use their existing load balancer to distribute traffic across two FortiGate units participating on a BGP network serving different neighbors. The customer has mixed traffic of IPv4 and IPv6 TCP, UDP, and ICMP. The two FortiGate devices shown in the exhibit should be redundant to each other so that the NAT session and active session tables will synchronize and fail over to the unit that is still operating without any loss of data if one of the units fail.
NSE8 dumps exhibit
Which high availability solution would you implement?

  • A. FortiGate Cluster Protocol (FGCP)
  • B. Fortinet redundant UTM protocol (FRUP)
  • C. FortiGate Session Life Support Protocol (FGSP)
  • D. Virtual Router Redundancy Protocol (VRRP)

Answer: A

Explanation: References:
http://docs.fortinet.com/uploaded/files/1074/fortigate-ha-40-mr2.pdf

NEW QUESTION 5
You notice that memory usage is high and FortiGate has entered conserve mode. You want FortiGate’s IPS engine to focus only on exploits and attacks that are applicable to your specific network.
Which two steps would you take to reduce RAM usage without weakening security? (Choose two.)

  • A. Configure IPS to pass files that are larger than a specific threshold, instead of buffering and scanning them.
  • B. Reduce the size of the signature three (filters) that FortiGate must search by disabling scans for applications and OS stacks that do not exist on your network.
  • C. Disable application control for protocols that are not used on your network.
  • D. Disable IPS for traffic destined for the FortiGate itself.

Answer: BD

NEW QUESTION 6
A customer wants to implement a RADIUS Single Sign On (RSSO) solution for multiple FortiGate devices. The customer’s network already includes a RADIUS server that can generate the logon and logoff accounting records. However, the RADIUS server can send those records to only one destination.
What should the customer do to overcome this limitation?

  • A. Send the RADIUS records to an LDAP server and add the LDAP server to the FortiGate configuration.
  • B. Send the RADIUS records to an RSSO Collector Agent.
  • C. Send the RADIUS records to one of the FortiGate devices, which can replicate them to the other FortiGate units.
  • D. Use the RADIUS accounting proxy feature available in FortiAuthenticator devices.

Answer: B

Explanation: References:
http://docs.fortinet.com/uploaded/files/1937/fortigate-authentication-52.pdf

NEW QUESTION 7
The SECOPS team in your company has started a new project to store all logging data in a disaster recovery center. All FortiGates will log to a secondary FortiAnalyzer and establish a TCP session to send logs to the syslog server.
Which two configurations will achieve this goal? (Choose two.)

  • A. NSE8 dumps exhibit
  • B. NSE8 dumps exhibit
  • C. NSE8 dumps exhibit
  • D. NSE8 dumps exhibit

Answer: AC

Explanation: https://forum.fortinet.com/tm.aspx?m=122848

NEW QUESTION 8
The FortiGate is an IPsec VPN hub. A VPN spoke protecting subnet 192.168.222.0/24 has successfully brought up a tunnel with the FortiGate. This remote network is present in the FortiGate routing table as shown in the exhibit.
NSE8 dumps exhibit
Which statement is true?

  • A. This subnet was learned during quick-mode negotiation and was dynamically injected into the routing table.
  • B. The FortiGate administrator configured this subnet as a locally connected subnet on the “BranchOffice” phase1 interface.
  • C. The route in the exhibit is bound to “BranchOffice_0” which is a tunnel other than “BranchOffice”.
  • D. The FortiGate administrator configured a static route for 192.168.222.0/24.

Answer: B

NEW QUESTION 9
A customer is authenticating users using a FortiGate and an external LDAP server. The LDAP user, John Smith, cannot authenticate. The administrator runs the debug command diagnose debug application fnbamd 255 while John Smith attempts the authentication:
Based on the output shown in the exhibit, what is causing the problem?
NSE8 dumps exhibit

  • A. The LDAP administrator password in the FortiGate configuration is incorrect.
  • B. The user, John Smith, does have an account in the LDAP server.
  • C. The user, John Smith, does not belong to any allowed user group.
  • D. The user, John Smith, is using an incorrect password.

Answer: A

Explanation: Fortigate not binded with LDAP server because of failed authentication. References:

NEW QUESTION 10
You have implemented FortiGate in transparent mode as shown in the exhibit. User1 from the Internet is trying to access the 192.168.10.10 Web servers.
NSE8 dumps exhibit
Which two statements about this scenario are true? (Choose two.)

  • A. User1 would be able to access the Web server intermittently.
  • B. User1 would not be able to access any of the Web servers at all.
  • C. FortiGate learns Web servers MAC address when the Web servers transmit packets.
  • D. FortiGate always flood packets to both Web servers at the same time.

Answer: AC

Explanation: Both servers have same ip address, so there will be intermittent we server connectivity from outside and whichever web server forwards packets fortigate learns its mac address.

NEW QUESTION 11
You are managing a FortiAnalyzer appliance. After an upgrade, you notice that the unit no longer displays historical logs, reports do not produce any data, and FortiView summary views are empty. However, you notice that the unit is receiving logs on the dashboard widgets.
Which step resolves this problem?

  • A. Execute the CLI command exec sql-local rebuild-db.
  • B. Execute the CLI command diag sql remove hcache.
  • C. Execute the CLI command exec sql-local reinsert-logs.
  • D. Restore the unit settings from a previous backup.

Answer: A

NEW QUESTION 12
Which two features are supported only by FortiMail but not by FortiGate? (Choose two.)

  • A. DNSBL
  • B. built-in MTA
  • C. end-to-end IBE encryption
  • D. FortiGuard Antispam

Answer: AB

NEW QUESTION 13
Your FortiGate has multiple CPUs. You want to verify the load for each CPU. Which two commands will accomplish this task? (Choose two.)

  • A. get system performance status
  • B. diag system mpstat
  • C. diag system cpu stat
  • D. diag system top

Answer: AD

Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=13825

NEW QUESTION 14
Referring to the diagram shown in the exhibit, you deployed VRRP load balancing using two FortiGate units and two VRRP groups with a VRRP virtual MAC address enabled on both FortiGate’s port2 interface. During normal operation, both FortiGate units are processing traffic and the VRRP groups are used to load balance the traffic between the two FortiGate units.
NSE8 dumps exhibit
If FortiGate unit A fails, what would happen?

  • A. The FortiGate Unit B port2 interface sends gratuitous ARPs to associate the VRRPvirtual router IP address with its own MAC address, and all traffic fails over to it.
  • B. The FortiGate Unit B port2 interface will use virtual MAC addresses of 00-00-5e-00-01- 05 and 00-00-5e-00-01-0a, and all traffic fails over to it.
  • C. The FortiGate Unit B port2 interface will use virtual MAC addresses of 00-a0-5e-00-01- 05 and 00-a0-5e-00-01-0a, and all traffic fails over to it.
  • D. The FortiGate Unit B port2 interface will use the physical MAC addresses of the FortiGate Unit A port2 interface, and all traffic fails over to it.

Answer: B

Explanation: If primary fails secondary device uses virtual mac address to forward traffic

NEW QUESTION 15
Referring to the exhibit, you want to know if aggregating port7 and port22 will work. Which statement is correct?
NSE8 dumps exhibit

  • A. Yes, LACP is supported on all ports regardless if they are connected to the same NP6.
  • B. No, LACP is not supported on NP6 platforms.
  • C. No, LACP is only supported on ports connected to the same NP6.
  • D. Yes, LACP is supported on ports that are linked together with integrated Switch Fabric.

Answer: C

Explanation: References:
http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-hardware-acceleration- 52/NP6.htm

NEW QUESTION 16
A customer wants to install a FortiSandbox device to identify suspicious files received by an e-mail server. All the incoming e-mail traffic to the e-mail server uses the SMTPS protocol.
Which three solutions would be implemented? (Choose three.)

  • A. FortiGate device in transparent mode sending the suspicious files to the FortiSandbox
  • B. FortiSandbox in sniffer input mode
  • C. FortiMail device in gateway mode using the built-in MTA and sending the suspicious files to the FortiSandbox
  • D. FortiMail device in transparent mode acting as an SMTP proxy sending the suspicious files to the FortiSandbox
  • E. FortiGate device in NAT mode sending the suspicious files to the FortiSandbox

Answer: BCE

Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=FD34371

P.S. 2passeasy now are offering 100% pass ensure NSE8 dumps! All NSE8 exam questions have been updated with correct answers: https://www.2passeasy.com/dumps/NSE8/ (65 New Questions)