Fortinet NSE8_811 考試概覽:
| 認證廠商: | Fortinet |
|---|---|
| 考試名稱: | Fortinet NSE 8 筆試考試(NSE8_811) |
| 考試代碼: | NSE8_811 |
| 考試時間: | 120 分鐘 |
| 相關認證: | NSE 8 實作考試 |
| 支援語言: | 英文 |
| 考試費用: | 400 美元 |
| 考試形式: | 搭配圖表/示意圖/設定內容, 單選題, 情境導向題型, 複選題 |
| 實際考試題數: | 60 |
| 證照有效期限: | 完整取得認證後3年內有效 |
| 及格分數: | 採及格/不及格制,不公布確切分數;每題皆須完全答對方可得分 |
| 推薦課程: | Fortinet NSE 8 準備資源 |
| 考試報名: | Pearson VUE 報名入口 Fortinet NSE 8 計畫官方頁面 |
| 範例考題: | Fortinet NSE8_811 範例考題 |
| 考試方式: | 於 Pearson VUE 考場實體應考,或透過 Pearson VUE OnVUE 線上監考方式應考 |
| 必備條件: | 無強制報考資格要求;建議具備 NSE 4 至 NSE 7 相關知識及5年以上企業資安領域經驗;須先通過筆試,方可報考 NSE 8 實作考試 |
| 官方大綱網址: | https://training.fortinet.com/local/staticpage/view.php?page=nse_8_staging |
Fortinet NSE8_811 考試大綱主題:
| 章節 | 權重 | 目標 |
|---|---|---|
| 資安網狀架構與多產品整合 | 25% | - FortiAuthenticator、FortiToken 身分識別管理 - FortiSandbox、FortiDDoS 威脅防護 - FortiSwitch、FortiAP 安全存取整合 - FortiManager、FortiAnalyzer 集中管理 |
| FortiGate 進階架構與部署 | 25% | - 高可用性(FGCP/FGSP)與叢集架構 - NPU 卸載、效能調校、核心除錯 - 複雜 NAT、IPsec VPN、SSL VPN 設計 - 進階路由:BGP、OSPF、VRF、路由重新分配 |
| SD-WAN 與廣域網路架構 | 20% | - 混合式廣域網路、網際網路/MPLS/5G 整合 - SD-WAN 架構下的資安強制策略 - SD-WAN 規則設計、服務等級協定、負載平衡 |
| 進階資安與威脅防護機制 | 20% | - 進階威脅防護、零信任架構 - 日誌記錄、報表產出、遵循法規設計 - 入侵防禦系統、應用程式控管、網頁過濾 |
| 複雜網路之設計與故障排除 | 10% | - 複雜問題的診斷與解決方案 - 端對端安全網路設計 |
最新的 Fortinet Network Security Expert NSE8_811 免費考試真題:
問題 #1
Click the Exhibit button. An administrator implements a multi-chassis link aggregation (MCLAG) solution using two FortiSwitch 448Ds and one FortiGate 3700D. As describes in the network topology shown in the exhibit, two links are connected to each FortiSwitch. What is requires to implement this solution? (Choose two.)
A. Create two separate link aggregated (LAG) interfaces on the FortiGate side for each FortiSwitch.
B. An ICL link between both FortiSwitch devices needs to be added.
C. Add set fortilink-split-interface disable on the FortiLink interface.
D. Replace the FortiGate as this one does not have an ISF.
問題 #2
Click the Exhibit button.
You have installed a FortiSandbox and configured it in your FortiMail. Referring to the exhibit, which two statements are correct? (Choose two.)
A. FortiMail will cache the results for 30 minutes.
B. If FortiMail is not able to obtain the results from the fortiGuard quenes. URls will not be checked by the FortiSandbox.
C. If the FortiSandbox with IP 10.10 10 3 is not available, the e-mail will be checked by the FortiCloud Sandbox.
D. FortiMail will wait for 30 minutes to obtain the scan results.
問題 #3
You are building a FortiGala cluster which is stretched over two locations. The HA connections for the cluster are terminated on the data centers. Once the FortiGates have booted, they do form a cluster. The network operators inform you that CRC eoors are present on the switches where the FortiGAtes are connected.
What would you do to solve this problem?
A. Change the ethertype for the HA packets.
B. Replace the caables where the CRC errors occur.
C. Set the speedduplex setting to 1 Gbps /Full Duplex.
D. Place the HA interfaces in dedicated VLANs.
問題 #4
Exhibit
Click the Exhibit button.
The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device.
Which two statements are true about the traffic matching being inspected by this SPP? (Choose two.)
A. Traffic that does match any spp policy will not be inspection by this spp.
B. FortiDDos will not send a SYNACK if a SYN packet is coming from an IP address that is not the legtimate IP (LIP) address table.
C. FortiDooS will start dropping packets as soon as the traffic executed the configured maintain threshold.
D. SYN packets with payloads will be drooped.
問題 #5
Refer to the exhibit.
You have two data centers with a FortiGate 7000-series chassis connected by VPN. All traffic flows over an established generic routing encapsulation (GRE) tunnel between them. You are troubleshooting traffic that is traversing between Server VLAN A and Server VLAN B.
The performance is lower than expected and you notice all traffic is only going through the FPM in slot 3 while nothing through the FPM in slot 4.
Referring to the exhibit, which statement is true?
A. Removing traffic shaping from the firewall policy allowing this traffic will allow for load-balancing to the other module.
B. Configuring a load-balance flow-rule in the CLI will load-balance this traffic.
C. Changing the algorithm to take source IP, destination IP and port into account will load balance this traffic to the other module.
D. There is no way to load-balance the traffic in this scenario.
問題與答案:
| 問題 #1 答案: B,C | 問題 #2 答案: B,D | 問題 #3 答案: A | 問題 #4 答案: A,D | 問題 #5 答案: B |

下載最新試用版
1442位客戶反饋
我們對我們的產品非常有信心,所以我們不提供会给客户带去麻煩的產品。








183.15.249.* -
真的好意外,我第一次就通過了 NSE8_811 考試。很感謝我的朋友推薦給我的 VCESoft 網站的考試資料,讓我以非常好的成績通過了NSE8_811考試。