Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet Exam NSE8_812 Topic 2 Question 31 Discussion

Actual exam question for Fortinet's NSE8_812 exam
Question #: 31
Topic #: 2
[All NSE8_812 Questions]

Refer to the CLI output:

Given the information shown in the output, which two statements are correct? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, D, E

Bmust be set to enable mode-cfg, which is required for injecting IKE routes on the ADVPN shortcut tunnels.

Dmust be set to enable add-route, which is the command that actually injects the IKE routes.

Emust be set to enable mode-cfg-allow-client-selector, which allows custom phase 2 selectors to be configured.

The other options are incorrect. Option A is incorrect because net-device disable is not required for injecting IKE routes on the ADVPN shortcut tunnels. Option C is incorrect because IKE version 1 is not supported for ADVPN.

References:

Phase 2 selectors and ADVPN shortcut tunnels | FortiGate / FortiOS 7.2.0

Configuring SD-WAN/ADVPN with FortiGate | FortiGate / FortiOS 7.2.0


Contribute your Thoughts:

Rosenda
11 days ago
I'm not sure about D. Just because an IP was previously used by an attacker doesn't mean it will always be blocked. That doesn't seem quite right.
upvoted 0 times
...
Odette
16 days ago
A and B seem like the correct options here. The output shows that the IP Reputation feature is enabled, and it can block attackers before they target the servers.
upvoted 0 times
...
Lavonda
19 days ago
I'm not sure about statement C, but I think D is also correct because an IP address used by an attacker will always be blocked.
upvoted 0 times
...
Annamaria
20 days ago
I agree with Haydee, attackers can be blocked before they target the servers and the IP Reputation feature has been manually updated.
upvoted 0 times
...
Haydee
21 days ago
I think the correct statements are B and C.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77