2017 Lead4pass Free Latest IT Cert Exam Dumps

High Quality Latest Microsoft, Cisco, CompTIA, VMware And Other IT Cert Exam Dumps With 100% Pass Guarantee

[2017 Latest Exam Dumps] Fortinet Network Security,NSE 5 NSE5 Dumps Exam Materials And Youtube Update Free Try

  • Fortinet
  • October 24, 2017
  • Comments Off on [2017 Latest Exam Dumps] Fortinet Network Security,NSE 5 NSE5 Dumps Exam Materials And Youtube Update Free Try

Update the latest Fortinet NSE5 dumps pdf and vce practice files. Download free latest Fortinet NSE5 dumps exam questions and answers at Lead4pass. https://www.lead4pass.com/NSE5.html dumps pdf practice files. Lead4pass offers high quality Fortinet NSE5 exam dumps training materials and study guides, pass Fortinet NSE5 exam test easily.

Latest Fortinet NSE5 dumps pdf training materials free download: https://drive.google.com/open?id=0B_7qiYkH83VRWXdPdGYwbHpWRnc

Latest Fortinet NSE4 dumps pdf training materials free download: https://drive.google.com/open?id=0B_7qiYkH83VRaE1sNFV5ems4Tmc

Vendor: Fortinet
Certifications: Network Security,NSE 5
Exam Name: Fortinet Network Security Expert 5 Written Exam (500)
Exam Code: NSE5
Total Questions: 239 Q&As
NSE5 dumps
QUESTION 1
What advantages are there in using a hub-and-spoke IPSec VPN configuration instead of a fully- meshed set of IPSec tunnels? (Select all that apply.)
A. Using a hub and spoke topology is required to achieve full redundancy.
B. Using a hub and spoke topology simplifies configuration because fewer tunnels are required.
C. Using a hub and spoke topology provides stronger encryption.
D. The routing at a spoke is simpler, compared to a meshed node.
Correct Answer: BD

QUESTION 2
FSSO provides a single sign on solution to authenticate users transparently to a FortiGate unit using credentials stored in Windows Active Directory. Which of the following statements are correct regarding FSSO in a Windows domain environment when NTLM and Polling Mode are not used? NSE5 dumps (Select all that apply.)
A. An FSSO Collector Agent must be installed on every domain controller.
B. An FSSO Domain Controller Agent must be installed on every domain controller.
C. The FSSO Domain Controller Agent will regularly update user logon information on the FortiGate unit.
D. The FSSO Collector Agent will retrieve user information from the Domain Controller Agent and will send the user logon information to the FortiGate unit.
E. For non-domain computers, the only way to allow FSSO authentication is to install an FSSO client.
Correct Answer: BD

QUESTION 3
For Data Leak Prevention, which of the following describes the difference between the block and quarantine actions?
A. A block action prevents the transaction. A quarantine action blocks all future transactions, regardless of the protocol.
B. A block action prevents the transaction. A quarantine action archives the data.
C. A block action has a finite duration. A quarantine action must be removed by an administrator.
D. A block action is used for known users. A quarantine action is used for unknown users.
Correct Answer: A

QUESTION 4
Which of the following represents the correct order of criteria used for the selection of a Master unit within a FortiGate High Availability (HA) cluster when master override is disabled?
A. 1. port monitor, 2. unit priority, 3. up time, 4. serial number
B. 1. port monitor, 2. up time, 3. unit priority, 4. serial number
C. 1. unit priority, 2. up time, 3. port monitor, 4. serial number
D. 1. up time, 2. unit priority, 3. port monitor, 4. serial number
Correct Answer: B

QUESTION 5
Examine the exhibit shown below then answer the question that follows it.
NSE5 dumps
Within the UTM Proxy Options, the CA certificate Fortinet_CA_SSLProxy defines which of the following:
A. FortiGate unit’s encryption certificate used by the SSL proxy.
B. FortiGate unit’s signing certificate used by the SSL proxy.
C. FortiGuard’s signing certificate used by the SSL proxy.
D. FortiGuard’s encryption certificate used by the SSL proxy.
Correct Answer: A

QUESTION 6
What are the requirements for a cluster to maintain TCP connections after device or link failover? (Select all that apply.)
A. Enable session pick-up.
B. Only applies to connections handled by a proxy.
C. Only applies to UDP and ICMP connections.
D. Connections must not be handled by a proxy.
Correct Answer: AD

QUESTION 7
Which of the following statements are correct regarding virtual domains (VDOMs)? NSE5 dumps (Select all that apply.)
A. VDOMs divide a single FortiGate unit into two or more virtual units that function as multiple, independent units.
B. A management VDOM handles SNMP, logging, alert email, and FDN-based updates.
C. VDOMs share firmware versions, as well as antivirus and IPS databases.
D. Only administrative users with a ‘super_admin’ profile will be able to enter multiple VDOMs to make configuration changes.
Correct Answer: ABC

QUESTION 8
Which of the following statements are correct regarding Application Control?
A. Application Control is based on the IPS engine.
B. Application Control is based on the AV engine.
C. Application Control can be applied to SSL encrypted traffic.
D. Application Control cannot be applied to SSL encrypted traffic.
Correct Answer: AC

QUESTION 9
Data Leak Prevention archiving gives the ability to store files and message data onto a FortiAnalyzer unit for which of the following types of network traffic? (Select all that apply.)
A. SNMP
B. IPSec
C. SMTP
D. POP3
E. HTTP
Correct Answer: CDE

QUESTION 10
With FSSO, a domain user could authenticate either against the domain controller running the Collector Agent and Domain Controller Agent, or a domain controller running only the Domain Controller Agent.
If you attempt to authenticate with the Secondary Domain Controller running only the Domain Controller Agent, which of the following statements are correct? (Select all that apply.)
A. The login event is sent to the Collector Agent.
B. The FortiGate unit receives the user information from the Domain Controller Agent of the Secondary Controller.
C. The Collector Agent performs the DNS lookup for the authenticated client’s IP address.
D. The user cannot be authenticated with the FortiGate device in this manner because each Domain Controller Agent requires a dedicated Collector Agent.
Correct Answer: AC

QUESTION 11
Which of the following statements are correct about the HA diag command diagnose sys ha reset-uptime? NSE5 dumps (Select all that apply.)
A. The device this command is executed on is likely to switch from master to slave status if master override is disabled.
B. The device this command is executed on is likely to switch from master to slave status if master override is enabled.
C. This command has no impact on the HA algorithm.
D. This command resets the uptime variable used in the HA algorithm so it may cause a new master to become elected.
Correct Answer: AD

QUESTION 12
In a High Availability cluster operating in Active-Active mode, which of the following correctly describes the path taken by the SYN packet of an HTTP session that is offloaded to a subordinate unit?
A. Request: Internal Host; Master FortiGate; Slave FortiGate; Internet; Web Server
B. Request: Internal Host; Master FortiGate; Slave FortiGate; Master FortiGate; Internet; Web Server
C. Request: Internal Host; Slave FortiGate; Internet; Web Server
D. Request: Internal Host; Slave FortiGate; Master FortiGate; Internet; Web Server
Correct Answer: A

Reference: https://www.lead4pass.com/NSE5.html dumps exam practice questions and answers free update.

Watch the video to learn more: https://youtu.be/l4AVJljMAOg

';