Pass C-HRHFC-2311 Brain Dump Updated Certification Sample Questions
Online C-HRHFC-2311 Test Brain Dump Question and Test Engine
NEW QUESTION # 65
The HTTP inspection process in web filtering follows a specific order when multiple features are enabled in the web filter profile. What order must FortiGate use when the web filter profile has features enabled, such as safe search?
- A. Static domain filter, SSL inspection filter, and external connectors filters
- B. DNS-based web filter and proxy-based web filter
- C. FortiGuard category filter and rating filter
- D. Static URL filter, FortiGuard category filter, and advanced filters
Answer: D
Explanation:
FortiGate Security 7.2 Study Guide (p.285): "Remember that the web filtering profile has several features. So, if you have enabled many of them, the inspection order flows as follows: 1. The local static URL filter 2. FortiGuard category filtering (to determine a rating) 3. Advanced filters (such as safe search or removing Active X components)"
NEW QUESTION # 66
Refer to the exhibit.
Given the routing database shown in the exhibit, which two statements are correct? (Choose two.)
- A. The port3 default route has the lowest metric.
- B. There will be eight routes active in the routing table.
- C. The ports default route has the highest distance.
- D. The port1 and port2 default routes are active in the routing table.
Answer: C,D
Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-identify-Inactive-Routes-in-the-Routing/ta-p/197595
NEW QUESTION # 67
Refer to the exhibit.
Refer to the FortiGuard connection debug output.
Based on the output shown in the exhibit, which two statements are correct? (Choose two.)
- A. One server was contacted to retrieve the contract information.
- B. FortiGate is using default FortiGuard communication settings.
- C. There is at least one server that lost packets consecutively.
- D. A local FortiManager is one of the servers FortiGate communicates with.
Answer: A,B
Explanation:
FortiGate Security 7.2 Study Guide (p.287-288): "Flags: D (IP returned from DNS), I (Contract server contacted), T (being timed), F (failed)" "By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."
NEW QUESTION # 68
FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.
In this scenario, which statement about VLAN IDs is true?
- A. The two VLAN subinterfaces can have the same VLAN ID only if they belong to different VDOMs.
- B. The two VLAN subinterfaces must have different VLAN IDs.
- C. The two VLAN subinterfaces can have the same VLAN ID only if they have IP addresses in different subnets.
- D. The two VLAN subinterfaces can have the same VLAN ID only if they have IP addresses in the same subnet.
Answer: C,D
NEW QUESTION # 69
In an explicit proxy setup, where is the authentication method and database configured?
- A. Authentication Rule
- B. Firewall Policy
- C. Proxy Policy
- D. Authentication scheme
Answer: D
NEW QUESTION # 70
Which three statements explain a flow-based antivirus profile? (Choose three.)
- A. Flow-based inspection optimizes performance compared to proxy-based inspection.
- B. The IPS engine handles the process as a standalone.
- C. FortiGate buffers the whole file but transmits to the client at the same time.
- D. Flow-based inspection uses a hybrid of the scanning modes available in proxy-based inspection.
- E. If a virus is detected, the last packet is delivered to the client.
Answer: A,C,D
NEW QUESTION # 71
An administrator wants to simplify remote access without asking users to provide user credentials.
Which access control method provides this solution?
- A. L2TP
- B. ZTNA access proxy
- C. ZTNA IP/MAC filtering mode
- D. SSL VPN
Answer: B
Explanation:
FortiGate Infrastructure 7.2 Study Guide (p.165): "ZTNA access proxy allows users to securely access resources through an SSL-encrypted access proxy. This simplifies remote access by eliminating the use of VPNs." This is true because ZTNA access proxy is a feature that allows remote users to access internal applications without requiring VPN or user credentials. ZTNA access proxy uses a secure tunnel between the user's device and the FortiGate, and authenticates the user based on device identity and context. The user only needs to install a lightweight agent on their device, and the FortiGate will automatically assign them to the appropriate application group based on their device profile. This simplifies remote access and enhances security by reducing the attack surface12
NEW QUESTION # 72
Refer to the exhibit.
The exhibit shows the FortiGuard Category Based Filter section of a corporate web filter profile.
An administrator must block access to download.com, which belongs to the Freeware and Software Downloads category. The administrator must also allow other websites in the same category.
What are two solutions for satisfying the requirement? (Choose two.)
- A. Set the Freeware and Software Downloads category Action to Warning.
- B. Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
- C. Configure a web override rating for download.com and select Malicious Websites as the subcategory.
- D. Configure a separate firewall policy with action Deny and an FQDN address object for *.download.com as destination address.
Answer: B,C
Explanation:
FortiGate Security 7.2 Study Guide (p.268-269): "If you want to make an exception, for example, rather than unblock access to a potentially unwanted category, change the website to an allowed category. You can also do the reverse. You can block a website that belongs to an allowed category." "Static URL filtering is another web filter feature. Configured URLs in the URL filter are checked against the visited websites. If a match is found, the configured action is taken. URL filtering has the same patterns as static domain filtering: simple, regular expressions, and wildcard." B) Configure a web override rating for download.com and select Malicious Websites as the subcategory.
This is true because a web override rating is a feature that allows the administrator to change the FortiGuard category of a specific website or domain, and apply a different action to it based on the web filter profile. By configuring a web override rating for download.com and selecting Malicious Websites as the subcategory, the administrator can block access to download.com, which belongs to the Freeware and Software Downloads category by default, without affecting other websites in the same category. The Malicious Websites category has the action Block in the web filter profile shown in the exhibit.
D) Configure a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively.
This is true because a static URL filter entry is a feature that allows the administrator to define custom rules for filtering specific URLs or domains, and apply an action to them based on the web filter profile. By configuring a static URL filter entry for download.com with Type and Action set to Wildcard and Block, respectively, the administrator can block access to download.com and any subdomains or paths under it, without affecting other websites in the Freeware and Software Downloads category. The static URL filter entries have higher priority than the FortiGuard category based filter entries in the web filter profile.
NEW QUESTION # 73
Which statement is correct regarding the use of application control for inspecting web applications?
- A. Application control does not require SSL inspection to identity web applications.
- B. Application control does not display a replacement message for a blocked web application.
- C. Application control signatures are organized in a nonhierarchical structure.
- D. Application control can identity child and parent applications, and perform different actions on them.
Answer: D
Explanation:
Application control is a feature that allows FortiGate to inspect and control the use of specific web applications on the network. When application control is enabled, FortiGate can identify child and parent applications, and can perform different actions on them based on the configuration.
NEW QUESTION # 74
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. Web filter in flow-based inspection
- B. Antivirus in flow-based inspection
- C. DNS filter
- D. Application control
- E. Web application firewall
Answer: A,B,D
Explanation:
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/739623/dns-filter-handled-by-ips-engine-in-flow-mode
NEW QUESTION # 75
Which two statements describe how the RPF check is used? (Choose two.)
- A. The RPF check is run on the first sent and reply packet of any new session.
- B. The RPF check is run on the first sent packet of any new session.
- C. The RPF check is run on the first reply packet of any new session.
- D. The RPF check is a mechanism that protects FortiGate and the network from IP spoofing attacks.
Answer: B,D
Explanation:
FortiGate Infrastructure 7.2 Study Guide (p.41): "The RPF check is a mechanism that protects FortiGate and your network from IP spoofing attacks by checking for a return path to the source in the routing table." "FortiGate performs an RPF check only on the first packet of a new session. That is, after the first packet passes the RPF check and FortiGate accepts the session, FortiGate doesn't perform any additional RPF checks on that session." A) The RPF check is a mechanism that protects FortiGate and the network from IP spoofing attacks.
This is true because the RPF check verifies that the source IP address of an incoming packet matches the reverse route for that address, meaning that the packet came from a legitimate source and not from an attacker who is trying to impersonate another host. This prevents IP spoofing attacks, where an attacker sends packets with a forged source IP address to bypass security policies or launch denial-of-service attacks1 C) The RPF check is run on the first sent packet of any new session.
This is true because the RPF check is performed only once per session, on the first packet sent by either the client or the server, depending on the direction of the session initiation. This reduces the processing overhead and improves performance2
NEW QUESTION # 76
What is the effect of enabling auto-negotiate on the phase 2 configuration of an IPsec tunnel?
- A. FortiGate automatically negotiates different encryption and authentication algorithms with the remote peer.
- B. FortiGate automatically brings up the IPsec tunnel and keeps it up, regardless of activity on the IPsec tunnel.
- C. FortiGate automatically negotiates a new security association after the existing security association expires.
- D. FortiGate automatically negotiates different local and remote addresses with the remote peer.
Answer: B
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=12069
FortiGate Infrastructure 7.2 Study Guide (p.264): "...then FortiGate might drop interesting traffic because of the absence of active SAs. To prevent this, you can enable Auto-negotiate. When you do this, FortiGate not only negotiates new SAs before the current SAs expire, but it also starts using the new SAs right away." "Another benefit of enabling Auto-negotiate is that the tunnel comes up and stays up automatically, even when there is no interesting traffic. When you enable Autokey Keep Alive and keep Auto-negotiate disabled, the tunnel does not come up automatically unless there is interesting traffic. However, after the tunnel is up, it stays that way because FortiGate periodically sends keep alive packets over the tunnel. Note that when you enable Auto-negotiate, Autokey Keep Alive is implicitly enabled."
NEW QUESTION # 77
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?
- A. Policy lookup will be disabled.
- B. By Sequence view will be disabled.
- C. Interface Pair view will be disabled.
- D. Search option will be disabled
Answer: C
Explanation:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47821
NEW QUESTION # 78
Refer to the exhibit.
The exhibit contains a network diagram, virtual IP, IP pool, and firewall policies configuration.
The WAN (port1) interface has the IP address 10.200. 1. 1/24.
The LAN (port3) interface has the IP address 10 .0.1.254. /24.
The first firewall policy has NAT enabled using IP Pool.
The second firewall policy is configured with a VIP as the destination address.
Which IP address will be used to source NAT the internet traffic coming from a workstation with the IP address 10.0. 1. 10?
- A. 10.200. 1. 100
- B. 10.200. 1. 10
- C. 10.200. 1. 1
- D. 10.200.3. 1
Answer: A
Explanation:
Policy 1 is applied on outbound (LAN-WAN) and policy 2 is applied on inbound (WAN-LAN). question is asking SNAT for outbound traffic so policy 1 will take place and NAT overload is in effect.
NEW QUESTION # 79
Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)
- A. DNS
- B. ping
- C. TWAMP
- D. udp-echo
Answer: C,D
NEW QUESTION # 80
An administrator has a requirement to keep an application session from timing out on port 80. What two changes can the administrator make to resolve the issue without affecting any existing services running through FortiGate? (Choose two.)
- A. Set the session TTL on the HTTP policy to maximum
- B. Set the TTL value to never under config system-ttl
- C. Create a new service object for HTTP service and set the session TTL to never
- D. Create a new firewall policy with the new HTTP service and place it above the existing HTTP policy.
Answer: B,C
NEW QUESTION # 81
Which statement regarding the firewall policy authentication timeout is true?
- A. It is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address after this timer has expired.
- B. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets coming from the user's source IP.
- C. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets coming from the user's source MAC.
- D. It is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address after this timer has expired.
Answer: B
NEW QUESTION # 82
......
Real SAP C-HRHFC-2311 Exam Dumps with Correct 184 Questions and Answers: https://www.exam4docs.com/C-HRHFC-2311-study-questions.html
SAP C-HRHFC-2311 Certification Real 2024 Mock Exam: https://drive.google.com/open?id=1vA9pFFUCAUWqliAVzGTs7WpJOZM-MROD

