[2024] Easy To Download C_HRHFC_2311 Actual Exam Dumps Resources
Uplift Your C_HRHFC_2311 Exam Marks With The Help of C_HRHFC_2311 Dumps
SAP C_HRHFC_2311 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 95
A network administrator has enabled SSL certificate inspection and antivirus on FortiGate. When downloading an EICAR test file through HTTP, FortiGate detects the virus and blocks the file. When downloading the same file through HTTPS, FortiGate does not detect the virus and the file can be downloaded.
What is the reason for the failed virus detection by FortiGate?
- A. The browser does not trust the FortiGate self-signed CA certificate.
- B. The selected SSL inspection profile has certificate inspection enabled.
- C. The EICAR test file exceeds the protocol options oversize limit.
- D. The website is exempted from SSL inspection.
Answer: B,D
Explanation:
SSL Inspection Profile, on the Inspection method there are 2 options to choose from, SSL Certificate Inspection or Full SSL Inspection. FG SEC 7.2 Studi Guide: Full SSL Inspection level is the only choice that allows antivirus to be effective.
NEW QUESTION # 96
In an explicit proxy setup, where is the authentication method and database configured?
- A. Authentication scheme
- B. Authentication Rule
- C. Firewall Policy
- D. Proxy Policy
Answer: A
NEW QUESTION # 97
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. get system arp
- B. get system performance status
- C. get system status
- D. diagnose sys top
Answer: A
Explanation:
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."
NEW QUESTION # 98
51 Which statement is correct regarding the inspection of some of the services available by web applications embedded in third-party websites?
- A. The application signature database inspects traffic only from the original web application server.
- B. The security actions applied on the web applications will also be explicitly applied on the third-party websites.
- C. FortiGuard maintains only one signature of each web application that is unique.
- D. FortiGate can inspect sub-application traffic regardless where it was originated.
Answer: D
Explanation:
Reference:
https://help.fortinet.com/fortiproxy/11/Content/Admin%20Guides/FPX-AdminGuide/300_System/303d_FortiG
NEW QUESTION # 99
Refer to the exhibit.
Refer to the FortiGuard connection debug output.
Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
- A. FortiGate is using default FortiGuard communication settings.
- B. A local FortiManager is one of the servers FortiGate communicates with.
- C. There is at least one server that lost packets consecutively.
- D. One server was contacted to retrieve the contract information.
Answer: A,D
Explanation:
FortiGate Security 7.2 Study Guide (p.287-288): "Flags: D (IP returned from DNS), I (Contract server contacted), T (being timed), F (failed)" "By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."
NEW QUESTION # 100
Consider the topology:
Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout.
The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.
What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)
- A. Set the maximum session TTL value for the TELNET service object.
- B. Create a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic, and set the new TELNET service object in the policy.
- C. Create a new service object for TELNET and set the maximum session TTL.
- D. Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not happen after 90 minutes.
Answer: B,C
NEW QUESTION # 101
When a firewall policy is created, which attribute is added to the policy to support recording logs to a FortiAnalyzer or a FortiManager and improves functionality when a FortiGate is integrated with these devices?
- A. Log ID
- B. Policy ID
- C. Sequence ID
- D. Universally Unique Identifier
Answer: D
Explanation:
FortiGate Security 7.2 Study Guide (p.67): "When creating firewall objects or policies, a universally unique identifier (UUID) attribute is added so that logs can record these UUIDs and improve functionality when integrating with FortiManager or FortiAnalyzer."
NEW QUESTION # 102
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On HQ-FortiGate, disable Diffie-Helman group 2.
- B. On Remote-FortiGate, set port2 as Interface.
- C. On HQ-FortiGate, set IKE mode to Main (ID protection).
- D. On both FortiGate devices, set Dead Peer Detection to On Demand.
Answer: B,C
Explanation:
"In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: main, and aggressive mode. Settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel."
NEW QUESTION # 103
Which of statement is true about SSL VPN web mode?
- A. The tunnel is up while the client is connected.
- B. It assigns a virtual IP address to the client.
- C. It supports a limited number of protocols.
- D. The external network application sends data through the VPN.
Answer: C
Explanation:
FortiGate_Security_6.4 page 575 - Web mode requires only a web browser, but supports a limited number of protocols.
NEW QUESTION # 104
Which of the following conditions must be met in order for a web browser to trust a web server certificate signed by a third-party CA?
- A. The web-server certificate must be installed on the browser.
- B. The CA certificate that signed the web-server certificate must be installed on the browser.
- C. The private key of the CA certificate that signed the browser certificate must be installed on the browser.
- D. The public key of the web server certificate must be installed on the browser.
Answer: B
NEW QUESTION # 105
Which certificate value can FortiGate use to determine the relationship between the issuer and the certificate?
- A. SMMIE Capabilities value
- B. Subject Key Identifier value
- C. Subject value
- D. Subject Alternative Name value
Answer: B
NEW QUESTION # 106
How does FortiGate act when using SSL VPN in web mode?
- A. FortiGate acts as an FDS server.
- B. FortiGate acts as router.
- C. FortiGate acts as an HTTP reverse proxy.
- D. FortiGate acts as DNS server.
Answer: C
Explanation:
Reference:
https://pub.kb.fortinet.com/ksmcontent/Fortinet-Public/current/Fortigate_v4.0MR3/fortigate-sslvpn-40-mr3.pdf
NEW QUESTION # 107
Which of the following statements about central NAT are true? (Choose two.)
- A. IP tool references must be removed from existing firewall policies before enabling central NAT .
- B. Source NAT, using central NAT, requires at least one central SNAT policy.
- C. Destination NAT, using central NAT, requires a VIP object as the destination address in a firewall.
- D. Central NAT can be enabled or disabled from the CLI only.
Answer: A,D
NEW QUESTION # 108
Which statement is correct regarding the security fabric?
- A. FortiGate devices must be operating in NAT mode.
- B. FortiManager is one of the required member devices.
- C. FortiGate Cloud cannot be used for logging purposes.
- D. A minimum of two Fortinet devices is required.
Answer: A
Explanation:
FortiGate Security 7.2 Study Guide (p.428): "You must have a minimum of two FortiGate devices at the core of the Security Fabric, plus one FortiAnalyzer or cloud logging solution. FortiAnalyzer Cloud or FortiGate Cloud can act as the cloud logging solution. The FortiGate devices must be running in NAT mode."
NEW QUESTION # 109
Which statement correctly describes the use of reliable logging on FortiGate?
- A. Reliable logging prevents the loss of logs when the local disk is full.
- B. Reliable logging is enabled by default in all configuration scenarios.
- C. Reliable logging is required to encrypt the transmission of logs.
- D. Reliable logging can be configured only using the CLI.
Answer: C
Explanation:
FortiGate Security 7.2 Study Guide (p.192): "if using reliable logging, you can encrypt communications using SSL-encrypted OFTP traffic, so when a log message is generated, it is safely transmitted across an unsecure network. You can choose the level of SSL protection used by configuring the enc-algorithm setting on the CLI."
NEW QUESTION # 110
You have enabled logging on a FortiGate device for event logs and all security logs, and you have set up logging to use the FortiGate local disk.
What is the default behavior when the local disk is full?
- A. Logs are overwritten and the first warning is issued when log disk use reaches the threshold of 75%.
- B. No new log is recorded after the warning is issued when log disk use reaches the threshold of 95%.
- C. No new log is recorded until you manually clear logs from the local disk.
- D. Logs are overwritten and the only warning is issued when log disk use reaches the threshold of 95%.
Answer: A
Explanation:
config log disk setting
set diskfull [ overwrite | nolog ]
Action to take when disk is full. The system can overwrite the oldest log messages or stop logging when the disk is full. (default --> overwrite) config log memory global-setting set full-first-warning-threshold {integer} Log full first warning threshold as a percent. (default --> 75) Reference:
https://docs.fortinet.com/document/fortigate/7.2.5/cli-reference/421620/config-log-disk-setting
https://docs.fortinet.com/document/fortigate/7.2.5/cli-reference/418620/config-log-memory-global-setting C) Logs are overwritten and the first warning is issued when log disk use reaches the threshold of 75%.
This is true because this is the default behavior of FortiGate when logging to the local disk. The local disk is the internal storage of FortiGate that can be used to store event logs and security logs. When the local disk is full, FortiGate will overwrite the oldest logs with the newest ones, and issue warnings at different thresholds of disk usage. The first warning is issued when log disk use reaches 75%, the second warning is issued when log disk use reaches 85%, and the final warning is issued when log disk use reaches 95%. The administrator can configure these thresholds and the action to take when the disk is full using the CLI command config log disk setting1
NEW QUESTION # 111
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?
- A. Add user accounts to the Ignore User List.
- B. Add user accounts to the FortiGate group fitter.
- C. Add user accounts to Active Directory (AD).
- D. Add the support of NTLM authentication.
Answer: A
NEW QUESTION # 112
Refer to the exhibit.
The exhibit displays the output of the CLI command: diagnose sys ha dump-by vcluster.
Which two statements are true? (Choose two.)
- A. FortiGate SN FGVM010000064692 has the higher HA priority.
- B. FortiGate SN FGVM010000064692 is the primary because of higher HA uptime.
- C. FortiGate SN FGVM010000065036 HA uptime has been reset.
- D. FortiGate devices are not in sync because one device is down.
Answer: A,C
Explanation:
1. Override is disable by default - OK
2. "If the HA uptime of a device is AT LEAST FIVE MINUTES (300 seconds) MORE than the HA Uptime of the other FortiGate devices, it becomes the primary" The question here is : HA Uptime of FGVM01000006492 > 5 minutes? NO - 198 seconds < 300 seconds (5 minutes) Page 314 Infra Study Guide. https://docs.fortinet.com/document/fortigate/6.0.0/handbook/666653/primary-unit-selection-with-override-disab
NEW QUESTION # 113
Refer to the exhibits.
Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.

Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)
- A. The traffic sourced from the client and destined to the server is sent to FGT-1.
- B. For non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source.
- C. For load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary.
- D. The cluster can load balance ICMP connections to the secondary.
Answer: B,C
Explanation:
FortiGate Infrastructure 7.2 Study Guide (p.317 & p.320): "To forward traffic correctly, a FortiGate HA solution uses virtual MAC addresses." "The primary forwards the SYN packet to the selected secondary. (...) This is also known as MAC address rewrite. In addition, the primary encapsulates the packet in an Ethernet frame type 0x8891. The encapsulation is done only for the first packet of a load balanced session. The encapsulated packet includes the original packet plus session information that the secondary requires to process the traffic."
NEW QUESTION # 114
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
- A. A session for denied traffic is created.
- B. Device detection on all interfaces is enforced for 30 minutes.
- C. The number of logs generated by denied traffic is reduced.
- D. Denied users are blocked for 30 minutes.
Answer: A,C
Explanation:
ses-denied-traffic
Enable/disable including denied session in the session table.
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/20620/config-system-settings block-session-timer Duration in seconds for blocked sessions .
integer
Minimum value: 1 Maximum value: 300
30
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/1620/config-system-global
NEW QUESTION # 115
What are two features of collector agent advanced mode? (Choose two.)
- A. In advanced mode, security profiles can be applied only to user groups, not individual users.
- B. In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
- C. Advanced mode supports nested or inherited groups.
- D. Advanced mode uses the Windows convention-NetBios: Domain\Username.
Answer: B,C
Explanation:
A) In advanced mode, FortiGate can be configured as an LDAP client and group filters can be configured on FortiGate.
This is true because advanced mode allows FortiGate to query the LDAP server directly for user information and group membership, without relying on the collector agent. This enables FortiGate to apply security policies based on LDAP group filters, which can be configured on FortiGate1 D) Advanced mode supports nested or inherited groups.
This is true because advanced mode can handle complex group structures, such as nested groups or inherited groups, where a user belongs to a group that is a member of another group. This allows FortiGate to apply security policies based on the effective group membership of a user, not just the direct group membership1 FortiGate Infrastructure 7.2 Study Guide (p.146): "Also, advanced mode supports nested or inherited groups; that is, users can be members of subgroups that belong to monitored parent groups." "In advanced mode, you can configure FortiGate as an LDAP client and configure the group filters on FortiGate. You can also configure group filters on the collector agent."
NEW QUESTION # 116
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network and the firewall policy and IP pool configuration on the FortiGate device.
Which two actions does FortiGate take on internet traffic sourced from the subscribers? (Choose two.)
- A. FortiGate generates a system event log for every port block allocation made per user.
- B. FortiGate allocates 128 port blocks per user.
- C. FortiGate allocates port blocks per user, based on the configured range of internal IP addresses.
- D. FortiGate allocates port blocks on a first-come, first-served basis.
Answer: A,D
Explanation:
FortiGate Security 7.2 Study Guide (p.109): "FortiGate allocates port blocks on a first-come, first-served basis." "For logging purposes, when FortiGate allocates a port block to a host, it generates a system event log to inform the administrator."
NEW QUESTION # 117
......
Use SAP C_HRHFC_2311 Dumps To Succeed Instantly in C_HRHFC_2311 Exam: https://www.vce4plus.com/SAP/C_HRHFC_2311-valid-vce-dumps.html
Ultimate Guide to C_HRHFC_2311 Dumps - Enhance Your Future Career Now: https://drive.google.com/open?id=1qoXxLnrIHiRrTa-1HAHTZ21Y1iDD0oA0