Question 76

A vulnerability scan report has revealed that a user has generated traffic to the website example.com (10.10.10.10) using a weak SSL/TLS version supported by the HTTPS web server.
What can the firewall administrator do to block all outdated SSL/TLS versions on any HTTPS web server to prevent possible attacks on user traffic?
  • Question 77

    Which parameter must be configured to modify the MED value?
  • Question 78

    Refer to the exhibit, which shows a network diagram showing the addition of site 2 with an overlapping network segment to the existing VPN IPsec connection between the hub and site 1.

    Which IPsec phase 2 configuration must an administrator make on the FortiGate hub to enable equal-cost multi-path (ECMP) routing when multiple remote sites connect with overlapping subnets?
  • Question 79

    Refer to the exhibit.

    An administrator wants to expand the network by adding two additional FortiGate devices into AS
    6500.
    Which configuration is the most effective way to improve BGP convergence in this scenario?
  • Question 80

    Refer to the exhibit, which shows the FortiGuard Distribution Network of a FortiGate device.
    FortiGuard Distribution Network on FortiGate

    An administrator is trying to find the web filter database signature on FortiGate to resolve issues with websites not being filtered correctly in a flow-mode web filter profile.
    Why is the web filter database version not visible on the GUI, such as with IPS definitions?