Which two statements are correct about NGFW Policy-based mode? (Choose two.)
A. NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy.
B. NGFW policy-based mode can only be applied globally and not on individual VDOMs.
C. NGFW policy-based mode does not require the use of central source NAT policy.
D. NGFW policy-based mode policies support only flow inspection.
Question 56
Refer to the exhibits.The exhibits contain a network diagram, virtual IP, IP pool, and firewall policies configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The first firewall policy has NAT enabled using IP Pool.The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0.1.10?
Refer to the web filter raw logs. Based on the raw logs shown in the exhibit, which statement is correct?
A. The name of the firewall policy is all_users_web.
B. Social networking web filter category is configured with the action set to authenticate.
C. The action on firewall policy ID 1 is set to warning.
D. Access to the social networking web filter category was explicitly blocked to all users.
Question 60
Refer to the exhibit. An administrator has configured a performance SLA on FortiGate, which failed to generate any traffic. Why is FortiGate not sending probes to 4.2.2.2 and 4.2.2.1 servers? (Choose two.)
A. The Detection Mode setting is not set to Passive.
B. Administrator didn't configure a gateway for the SD-WAN members, or configured gateway is not valid.
C. The configured participants are not SD-WAN members.
D. The Enable probe packets setting is not enabled.