NSE8_813 Exam Question 11

An administrator has configured a FortiGate device to authenticate SSL VPN users using digital certificates. A FortiAuthenticator is the certificate authority (CA) and the Online Certificate Status Protocol (OCSP) server.
Part of the FortiGate configuration is shown below:

Based on this configuration, which statement is true?
  • NSE8_813 Exam Question 12

    You must configure an environment with dual-homed servers connected to a pair of FortiSwitch units using an MCLAG.
    Multicast traffic is expected in this environment, and should ensure unnecessary traffic is pruned from links that do not have a multicast listener.
    In which two ways must you configure the igmps-flood-traffic and igmps-flood-report settings?
    (Choose two.)
  • NSE8_813 Exam Question 13

    Review the following FortiGate-6000 configuration excerpt:

    Based on the configuration, which statement is correct regarding SNAT source port partitioning behavior?
  • NSE8_813 Exam Question 14

    Refer to the exhibits, which show a firewall policy configuration and a network topology.
    Configuration

    Topology

    An administrator has configured an inbound SSL inspection profile on a FortiGate device (FG-1) that is protecting a data center hosting multiple web pages.
    Given the scenario shown in the exhibits, which certificate will FortiGate use to handle requests to xyz.com?
  • NSE8_813 Exam Question 15

    A customer wants to use a central RADIUS server for management authentication when connecting to the FortiGate GUI and to provide different levels of access for different types of employees.
    Which three actions are required to provide the requested functionality? (Choose three.)