ACTUAL Exam Questions and CORRECT
Answers
3 Types of hardware accelerators - CORRECT ANSWER - Content Processors
Network Processors
Security Processors
Content Processors (CP's) Definition - CORRECT ANSWER - -Not Bound to an Interface
-Encrypts and Decrypts SSL
-Processes Antivirus
CP8 and CP9 - CORRECT ANSWER - -Can offload Antivirus Flow Based Pattern
Matching to these chips
-Can offload IPS pattern matching to these chips
Network Processors (NP's) Definition - CORRECT ANSWER - Directly attached to
network interface
Packet Processing
NP4 and NP6 - CORRECT ANSWER - Can offload IPS with NTurbo
NTurbo - CORRECT ANSWER - Can offload IPS Processing to CP8, CP9, NP4, NP6,
SoC3 Depending on Model.
Security Processors (SP's) Definition - CORRECT ANSWER - Directly attached to
network interfaces
Can accelerate IPS
, System on a Chip (SoC3) - CORRECT ANSWER - On entry level devices
SoC3 platform includes NTurbo
Debugging Verbosity Level Numbers - CORRECT ANSWER - 3- Print header and data
from ethernet of packet.
4- Prints the ingress and egress interfaces, can verify how packet is being routed and if its
dropped
6- print header and data from Ethernet of packets with interface name
Web Application Firewall (WAF) - CORRECT ANSWER - -Available only in Proxy
Inspection Mode.
-Secures Servers that receive connections instead of initiate.
-Blocks Cross Site Scripting (XSS) and SQL Injection.
FortiWeb - CORRECT ANSWER - -A Special WAF device.
-Can be configured behind FortiGate or as one arm sniffer.
-Can forward to external FortiWeb.
Default FW Mode - CORRECT ANSWER - Flow based with NGFW mode set to Profile-
Based
Antivirus Security Profile - CORRECT ANSWER - Always profile based regardless of
NGFW Mode.
Fortigate Cluster Protocol (FGCP) - CORRECT ANSWER - -Travels between HA Cluster
members over Heartbeat interfaces.
-Uses Port 703 for communication.
-Uses port 23 fro transferring configurations and syncing.