2026 New NSE8 Exam Dumps with PDF and VCE Free: https://www.surepassexam.com/NSE8-exam-dumps.html
Want to know features? Want to lear more about experience? Study . Gat a success with an absolute guarantee to pass Fortinet NSE8 (NSE8) test on your first attempt.
Free demo questions for Fortinet NSE8 Exam Dumps Below:
NEW QUESTION 1
A FortiGate is deployed in the NAT/Route operation mode. This operation mode operates at which OSI layer?
- A. Layer 4
- B. Layer 1
- C. Layer 3
- D. Layer 2
Answer: C
NEW QUESTION 2
Your marketing department uncompressed and executed a file that the whole department received using Skype.
Reviewing the exhibit, which two details do you determine from your initial analysis of the payload?
- A. The payload contains strings that the malware is monitoring to harvest credentials.
- B. This is a type of Trojan that will download and pirate movies using your Netflix credentials.
- C. This type of threat of a DDoS attack using instant messaging to send e-mails to further spread the infection.
- D. This threat payload is uploading private user videos which are then used to extort Bitcoin payments.
Answer: B
NEW QUESTION 3
The exhibit shows an explicit Web proxy configuration in a FortiGate device. The FortiGate is installed between a client with the IP address 172.16.10.4 and a Web server using port 80 with the IP address 10.10.3.4. The client Web browser is properly sending HTTP traffic to the FortiGate Web proxy IP address 172.16.10.254.
Which two sniffer commands will capture this HTTP traffic? (Choose two.)
- A. diagnose sniffer packet any ‘host 172.16.10.4 and host 172.16.10.254’ 3
- B. diagnose sniffer packet any ‘host 172.16.10.254 and host 10.10.3.4’ 3
- C. diagnose sniffer packet any ‘host 172.16.10.4 and port 8080’ 3
- D. diagnose sniffer packet any ‘host 172.16.10.4 and host 10.10.3.4’ 3
Answer: CD
Explanation: Sniffer should run between webproxy to webserver
And also Sniffer between client machine to web proxy connectivity as it is in explicit mode.
References:
NEW QUESTION 4
Referring to the diagram shown in the exhibit, you deployed VRRP load balancing using two FortiGate units and two VRRP groups with a VRRP virtual MAC address enabled on both FortiGate’s port2 interface. During normal operation, both FortiGate units are processing traffic and the VRRP groups are used to load balance the traffic between the two FortiGate units.
If FortiGate unit A fails, what would happen?
- A. The FortiGate Unit B port2 interface sends gratuitous ARPs to associate the VRRPvirtual router IP address with its own MAC address, and all traffic fails over to it.
- B. The FortiGate Unit B port2 interface will use virtual MAC addresses of 00-00-5e-00-01- 05 and 00-00-5e-00-01-0a, and all traffic fails over to it.
- C. The FortiGate Unit B port2 interface will use virtual MAC addresses of 00-a0-5e-00-01- 05 and 00-a0-5e-00-01-0a, and all traffic fails over to it.
- D. The FortiGate Unit B port2 interface will use the physical MAC addresses of the FortiGate Unit A port2 interface, and all traffic fails over to it.
Answer: B
Explanation: If primary fails secondary device uses virtual mac address to forward traffic
NEW QUESTION 5
You have deployed two FortiGate devices as an HA pair. One FortiGate will process traffic while the other FortiGate is a standby. The standby monitors the primary for failure and only takes the role of processing traffic if it detects that the primary FortiGate has failed.
Which style of FortiGate HA does this scenario describe?
- A. active-passive HA
- B. active-active HA
- C. partial mesh HA
- D. full mesh HA
Answer: A
NEW QUESTION 6
A customer just bought an additional FortiGate device and plans to use their existing load balancer to distribute traffic across two FortiGate units participating on a BGP network serving different neighbors. The customer has mixed traffic of IPv4 and IPv6 TCP, UDP, and ICMP. The two FortiGate devices shown in the exhibit should be redundant to each other so that the NAT session and active session tables will synchronize and fail over to the unit that is still operating without any loss of data if one of the units fail.
Which high availability solution would you implement?
- A. FortiGate Cluster Protocol (FGCP)
- B. Fortinet redundant UTM protocol (FRUP)
- C. FortiGate Session Life Support Protocol (FGSP)
- D. Virtual Router Redundancy Protocol (VRRP)
Answer: A
Explanation: References:
http://docs.fortinet.com/uploaded/files/1074/fortigate-ha-40-mr2.pdf
NEW QUESTION 7
You verified that application control is working from previous configured categories. You just added Skype on blocked signatures. However, after applying the profile to your firewall policy, clients running Skype can still connect and use the application.
What are two causes of this problem? (Choose two.)
- A. The application control database is not updated.
- B. SSL inspection is not enabled.
- C. A client on the network was already connected to the Skype network and serves as relay prior to configuration changes to block Skype
- D. The FakeSkype.botnet signature is included on your application control sensor.
Answer: AB
NEW QUESTION 8
A customer wants to secure the network shown in the exhibit with a full redundancy design. Which security design would you use?
- A. Place a FortiGate FGCP Cluster between DD and AA, then connect it to SW1, SW2, SW3, and SW4.
- B. Place a FortiGate FGCP Cluster between BB and CC, then connect it to SW1, SW2, SW3, and SW4.
- C. Place a FortiGate FGCP Cluster between BB and AA, then connect it to SW1, SW2, SW3, and SW4.
- D. Place a FortiGate FGCP Cluster between DD and FF, then connect it to SW1, SW2, SW3, and SW4.
Answer: A
NEW QUESTION 9
Your FortiGate has multiple CPUs. You want to verify the load for each CPU. Which two commands will accomplish this task? (Choose two.)
- A. get system performance status
- B. diag system mpstat
- C. diag system cpu stat
- D. diag system top
Answer: AD
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=13825
NEW QUESTION 10
Given the following FortiOS 5.2 commands:
Which vulnerability is being addresses when managing FortiGate through an encrypted management protocol?
- A. Remote Exploit Vulnerability in Bash (ShellShock)
- B. Information Disclosure Vulnerability in OpenSSL (Heartbleed)
- C. SSL v3 POODLE Vulnerability
- D. SSL/TLS MITM vulnerability (CVE-2014-0224)
Answer: C
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=FD36913
NEW QUESTION 11
You must establish a BGP peering with a service provider. The provider has supplied you with BGP peering parameters and you performed the basic configuration shown in the exhibit on your FortiGate unit. You notice that your peering session is not coming up.
Which three missing configuration statements are needed to make this configuration functional? (Choose three.)
- A.

- B.

- C.

- D.

- E.

Answer: CDE
NEW QUESTION 12
The wireless controller diagnostic output is shown in the exhibit. Which three statements are true? (Choose three.)
- A. Firewall policies using device types are blocking Android devices.
- B. An access control list applied to the VAP interface blocks Android devices.
- C. This is a CAPWAP control channel diagnostic command.
- D. There are no wireless clients connected to the guest wireless network.
- E. The “src-vis” process is active on the staff wireless network VAP interface.
Answer: ACD
Explanation: References:
http://docs.fortinet.com/uploaded/files/1083/fortigate-managing-devices-50.pdf
NEW QUESTION 13
You have received an issue report about users not being able to use a video conferencing application. This application uses two UDP ports and two TCP ports to communicate with servers on the Internet. The network engineering team has confirmed there is no routing problem. You are given a copy of the FortiGate configuration.
Which three configuration objects will you inspect to ensure that no policy is blocking this traffic? (Choose three.)
- A. config firewall interface-policy
- B. config firewall DoS-policy
- C. config firewall policy
- D. config firewall multicast-policy
- E. config firewall sniffer-policy
Answer: BCE
NEW QUESTION 14
You are hosting Web applications that must be PCI DSS compliant. The Web applications are protected by a FortiWeb. Compliance will be tested during the quarterly security review.
In this scenario, which three FortiWeb features should you use? (Choose three.)
- A. Vulnerability Scan
- B. Auto-learning
- C. Syn Cookie
- D. Credit Card Detection
- E. the command.
Answer: ACD
Explanation: References:
http://help.fortinet.com/fweb/551/Content/FortiWeb/fortiweb-admin/web_protection.htm
NEW QUESTION 15
You have replaced an explicit proxy Web filter with a FortiGate. The human resources department requires that all URLs be logged. Users are reporting that their browsers are now indicating certificate errors as shown in the exhibit.
Which step is a valid solution to the problem?
- A. Make sure that the affected users’ browsers are no longer set to use the explicit proxy.
- B. Import the FortiGate’s SSL CA certificate into the Web browsers.
- C. Change the Web filter policies on the FortiGate to only do certificate inspection.
- D. Make a Group Policy to install the FortiGate’s SSL certificate as a trusted host certificate on the Web browser.
Answer: D
Explanation: For https traffic inspection, client machine should install fortigate’s ssl certificate
NEW QUESTION 16
FortiGate1 has a gateway-to-gateway IPsec VPN to FortiGate2. The entire IKE negotiation between FortiGate1 and FortiGate2 is on UDP port 500. A PC on FortuGate2’s local area network is sending continuous ping requests over the VPN tunnel to a PC of FortiGate1’s local area network. No other traffic is sent over the tunnel.
Which statement is true on this scenario?
- A. FortiGate1 sends an R-U-THERE packet every 300 seconds while ping traffic is flowing.
- B. FortiGate1 sends an R-U-THERE packet if pings stop for 300 seconds and no IKE packet is received during this period.
- C. FortiGate1 sends an R-U-THERE packet if pings stop for 60 seconds and no IKE packet is received during this period.
- D. FortiGate1 sends an R-U-THERE packet every 60 seconds while ping traffic is flowing.
Answer: C
Explanation: References: http://kb.fortinet.com/kb/documentLink.do?externalID=FD35337
P.S. Certleader now are offering 100% pass ensure NSE8 dumps! All NSE8 exam questions have been updated with correct answers: https://www.certleader.com/NSE8-dumps.html (65 New Questions)