A network administrator is configuring a new IPsec VPN tunnel on FortiGate. The remote peer IP address is dynamic. In addition, the remote peer does not support a dynamic DNS update service. What type of remote gateway should the administrator configure on FortiGate for the new IPsec VPN tunnel to work?
A. Dialup User
B. Static IP Address
C. Pre-shared Key
D. Dynamic DNS
Dialup user is used when the remote peer's IP address is unknown. The remote peer whose IP address is unknown acts as the dialup clien and this is often the case for branch offices and mobile VPN clients that use dynamic IP address and no dynamic DNS
Question 33
An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel. Which DPD mode on FortiGate will meet the above requirement?
Refer to the exhibit. Review the Intrusion Prevention System (IPS) profile signature settings. Which statement is correct in adding the FTP.Login.Failed signature to the IPS sensor profile?
A. Traffic matching the signature will be silently dropped and logged.
B. The signature setting uses a custom rating threshold.
C. The signature setting includes a group of other signatures.
D. Traffic matching the signature will be allowed and logged.
Question 37
Refer to the exhibit. The exhibit shows the IPS sensor configuration. If traffic matches this IPS sensor, which two actions is the sensor expected to take? (Choose two.)
A. The sensor will block all attacks aimed at Windows servers.
B. The sensor will gather a packet log for all matched traffic.
C. The sensor will allow attackers matching the NTP.Spoofed.KoD.DoS signature.
D. The sensor will reset all connections that match these signatures.
Question 38
Which two attributes are required on a certificate so it can be used as a CA certificate on SSL Inspection? (Choose two.)
A. The CA extension must be set to TRUE.
B. The issuer must be a public CA.
C. The common name on the subject field must use a wildcard name.
D. The keyUsage extension must be set to keyCertSign.
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded. What is the reason for the failed virus detection by FortiGate?
A. Antivirus definitions are not up to date.
B. SSL/SSH Inspection profile is incorrect.
C. Antivirus profile configuration is incorrect.
D. Application control is not enabled.
Question 40
Which two protocols are used to enable administrator access of a FortiGate device? (Choose two.)