The CLI command set intelligent-mode
Correct Answer:
C
Configuring IPS intelligenceStarting with FortiOS 5.2, intelligent-mode is a new adaptive detection method. This command is enabled the default and it means that the IPS engine will perform adaptive scanning so that, for some traffic, the FortiGate can quickly finish scanning and offload the traffic to NPU or kernel. It is a balanced method which could cover all known exploits. When disabled, the IPS engine scans every single byte.
config ips globalset intelligent-mode {enable|disable}end
What is the purpose of an internal segmentation firewall (ISFW)?
Correct Answer:
C
ISFW splits your network into multiple security segments. They serve as a breach containers from attacks that come from inside.
View the following FortiGate configuration.
All traffic to the Internet currently egresses from port1. The exhibit shows partial session information for Internet traffic from a user on the internal network:
If the priority on route ID 1 were changed from 5 to 20, what would happen to traffic matching that user’s session?
Correct Answer:
A
http://kb.fortinet.com/kb/documentLink.do?externalID=FD40943
View the exhibit, which contains the output of a diagnose command, and then answer the question below.
What statements are correct regarding the output? (Choose two.)
Correct Answer:
AC
Refer to the exhibit, which contains the output of get system ha status. Which two statements about the output are true? (Choose two.)
Correct Answer:
BC