| Exam Code/Number: | NSE8Join the discussion |
| Exam Name: | Fortinet Network Security Expert 8 Written Exam (NSE8 801 - FortiOS 5.2) |
| Certification: | Fortinet |
| Question Number: | 65 |
| Publish Date: | Aug 26, 2026 |
|
Rating
100%
|
|
A company wants to protect against Denial of Service attacks and has launched a new project.
They want to block the attacks that go above a certain threshold and for some others they are just trying to get a
baseline of activity for those types of attacks so they are letting the traffic pass through without action.
Given the following:
-The interface to the Internet is on WAN1.
-There is no requirement to specify which addresses are being protected or protected from.
-The protection is to extend to all services.
-The tcp_syn_flood attacks are to be recorded and blocked.
-The udp_flood attacks are to be recorded but not blocked.
-The tcp_syn_flood attack's threshold is to be changed from the default to 1000.
The exhibit shows the current DoS-policy.
Which policy will implement the project requirements?
A:
B:
C:
D:
Referring to the diagram shown on the exhibit, you deployed VRRP load balancing using two FortiGate
units and two VRRP groups with a VRRP virtual MAC address enabled on both FortiGate's port2 interface.
During normal operation, both FortiGate units are processing traffic and the VRRP groups are used to
load balance the traffic between the two FortiGate units.
If FortiGate unit A fails, what would happen?
You have received an issue report about users not being able to use a video conferencing application.
This application uses two UDP ports and two TCP ports to communicate with servers on the Internet.
The network engineering team has confirmed there is no routing problem. You are given a copy of the
FortiGate configuration .
Which three configuration objects will you inspect to ensure that no policy is blocking this traffic? (Choose
three.)
You want to enable traffic between 2001:db8:1::/64 and 2001:db8:2::/64 over the public 1Pv4 Internet.
Given the CLI configuration shown on the exhibit, which two additional settings are required on this device
to implement tunneling for the 1Pv6 transition? (Choose two.)