单选题

The CLI command set intellient mode enable|disable>controls the IPS engine's adaptive scanning behavior.Which of the fol lowing statements describes IPS adaptive

scanning?【CLI命令set intelligent-mode控制IPS引擎的自适应扫描行为。下面哪个陈述描述了IPS自适应扫描?】 

A、

Determines the optimal number of IP S engines required based on system load.【根据系统负载确定所需的IPS引擎的最佳数量。】

B、

Downloads signatures ondemand fr o mFDS based on scanning requirements.【根据扫描要求从FDS按需下载签名。】

C、

Determines when it is secure enough 1tostop scanning session traffic.【确定何时足够安全,可以停止扫描会话流量。】

D、

Choose a matching algorithm based on available memory and the type of inspection being performed.【根据可用内存和正在执行的检K 查类型选择匹配算法。】

下载APP答题
由4l***38提供 分享 举报 纠错

相关试题

单选题 Refer to exhibit, which contains the output of a BGP debug command.【查看下列图片,其中包含BGP调试命令的输出。】

1667981984546.png

Which statement explains why the state of the 10.200.3.1peeris Connect?【哪条语句解释了为什么10.200.3.1邻居的状态是Connect?】

A、

The local router is receiving BGP keepalives from the remote peer, but the local peer has not received the Open Confirm yet.【本地路由器收到远端邻居发来的BGP keepalive报文, 但是本地对等体还没有收到Open Confirm消息。】

B、

The TCP session to 10.200.3.1 has not completed the 3-way handshake.【到10.200.3.1的TCP会话没有完成3次握手。】

C、

The local router is receiving the BGP keepalives from the peer, but it has not received a BGP prefix yet.【本地路由器收到邻居发来的BGP keepalive报文, 但还没有收到BGP前缀。】

D、

The local router has received the BGP prefixes from the remote peer.【本地路由器收到远端对等体发来的BGP前缀。】

单选题 When using the SSL certificate inspection method for HTTPS trafic, how does FortiGate filter web requests when the browser client does not provide the servername indication(SNI) extension?【当对HTTPS流量使用SSL证书检查方法时, 当浏览器客户端没有提供服务器名称指示(SNI) 扩展时, FortiGate如何过滤web请求?】

A、

FortiGate uses CN information from the Subject field in the server's certificate.【FortiGate使用来自服务器证书中的Subject字段的CN信息。】

B、

FortGate switches to the full SSL inspection method to decrypt the data.【FortiGate切换到完整的SSL检查方法来解密数据。】

C、

FortiGate blocks the request without any further inspection.【FortiGate会在没有任何进一步检查的情况下阻止请求。】

D、

FortiGate uses the requested URL from the user's webbrowser.【FortiGate使用来自用户web浏览器的请求URL。】

单选题 An administrator has configured two FortiGate devices for an HA cluster.While testing the HA failover, the administrator noticed that some of the switches in the network continue to send traffic to the former primary unit.The administrator decides to enable the set tng link-failed-signal to fix the problem.Which statement is correct regarding this command?【管理员为HA集群配置了两台FortiGate设备。在测试HA故障转移时, 管理员注意到网络中的一些交换机继续向以前的主单元发送流量。管理员决定启用设置的link-failed-signal来修复问题。关于这个命令, 哪条语句是正确的?】

A、

Forces the former primary device to shutdown all its non-heartbeat interfaces for one second while the failover occurs.【在故障切换发生时, 强制前主设备关闭所有非心跳接口1秒。】

B、

Send san ARP packet to all connected devices, indicating that the HA virtual MAC address is reachable through a new master after a failover.【向所有连接的设备发送ARP报文, 表示故障切换后, HA虚拟MAC地址可以通过新的主机到达。】

C、

Sends a link failed signal to all connected devices.【向所有连接的设备发送链路故障信号。】

D、

Disables all the non-heartbeat interfaces in all the HA members for two seconds after afailover.【故障切换后关闭所有HA成员的所有非心跳接口2秒。】

单选题 1、When using the SSL Q certificate inspection method to inspect HTTPS trafic, how does FortiGate filter web requests when the client browser does not provide the servername indication (SNI) extension?【当使用SSL证书检查方法检查HTTPS流量时, 当客户端浏览器没有提供服务器名称指示(SNI) 扩展时, FortiGate如何过滤web请求?】

A、

FortiGate uses the requested URL from the user's webbrowser.【FortiGate使用来自用户web浏览器的请求URL。】

B、

FortiGate uses the CN information from the Subject field in the server certificate.【FortiGate 使用来自服务器证书中的Subject字段的CN信息。】

C、

FortiGate blocks the request without any further inspection.【FortiGate会在没有任何进一步检查的情况下阻止请求。】

D、

FortiGate switches to the full SSL inspection method to decrypt the data.【FortiGate切换到完整的SSL检查方法来解密数据。】

单选题 Which statement is true regarding File description(FD) conserve mode?【关于文件描述(FD) 保护模式,哪句话是正确的?】 (单选题,1.00分)

A、

IPS inspection is affected when FortiGate enters FD conserve mode.【当FortiGate进入FD 保护模式时, 会影响IPS检测。】

B、

A FortiGate enters FD conserve mode when the amount of available description is less than 5%.【当可用描述的数量小于5%时, FortiGate进入FD保护模式。】

C、

FD conserve mode affects all daemons running on the device.【FD保护模式影响设备上运行的所有守护进程。】

D、

Restarting the WAD process is required to leave FD conserve mode.【需要重新启动WAD进程才能离开FD保护模式。】

单选题 View these partial out pu ots from two routing debug commands:【查看两个路由调试命令的部分输出:】

1667981894586.png

Which outbound interface will FortiGate use to route web traffic from internal users to the Internet?【FortiGate将使用哪个出站接口将内部用户的网络流量路由到Internet?】

A、

Both Port1 and port2

B、

Port3

C、

Port1

D、

Port2

单选题 Examine the partial output from two web fit er debug commands; then answer the question below:【检查两个web过滤器调试命令的部分输出; 然后回答以下问题:】

1667980384805.png

Based on the above outputs, which is the FortiGuard web fit er category for the website www.fgt99.com?【基于以上输出,网站www.fgt99.com是哪个FortiGuard网站过滤器类别?】

A、

Finance and banking.【金融和银行】

B、

General organization.〖一般组织】

C、

Business.【商业】

D、

Information technology.【信息技术】

单选题 Two independent FortiGate HA clusters are connected to the same broadcast domain.The administrator has reported that both clusters are using the same HA virtual MAC address.This

creates a duplicated MAC address problem in the network.What HA setting must be changed in one of the HA clusters to fix the problem?【两个独立的FortiGate HA集群连接到同一个广播域。管理员报告两个集群使用相同的HA虚拟MAC地址。这将在网络中产生一个重复的MAC地址问题。要解决这个问题,必须在某个HA集群中更改什么HA设置?】

A、

GroupID.【组ID】

B、

Group name.【组名】

C、

Session pickup.【会话拾取】

D、

Gratuitous ARPs.【免费ARP】