[Jul 28, 2024] Genuine C_HRHFC_2311 Exam Dumps New 2024 SAP Pratice Exam
New 2024 Realistic C_HRHFC_2311 Dumps Test Engine Exam Questions in here
NEW QUESTION # 13
Which two statements explain antivirus scanning modes? (Choose two.)
- A. In flow-based inspection mode, files bigger than the buffer size are scanned.
- B. In proxy-based inspection mode, files bigger than the buffer size are scanned.
- C. In proxy-based inspection mode, antivirus scanning buffers the whole file for scanning, before sending it to the client.
- D. In flow-based inspection mode, FortiGate buffers the file, but also simultaneously transmits it to the client.
Answer: C,D
Explanation:
An antivirus profile in full scan mode buffers up to your specified file size limit. The default is 10 MB. That is large enough for most files, except video files. If your FortiGate model has more RAM, you may be able to increase this threshold. Without a limit, very large files could exhaust the scan memory. So, this threshold balances risk and performance. Is this tradeoff unique to FortiGate, or to a specific model? No. Regardless of vendor or model, you must make a choice. This is because of the difference between scans in theory, that have no limits, and scans on real-world devices, that have finite RAM. In order to detect 100% of malware regardless of file size, a firewall would need infinitely large RAM--something that no device has in the real world. Most viruses are very small. This table shows a typical tradeoff. You can see that with the default 10 MB threshold, only 0.01% of viruses pass through.
FortiGate Security 7.2 Study Guide (p.350 & 352): "In flow-based inspection mode, the IPS engine reads the payload of each packet, caches a local copy, and forwards the packet to the receiver at the same time. Because the file is ransmitted simultaneously, flow-based mode consumes more CPU cycles than proxy-based." "Each protocol's proxy picks up a connection and buffers the entire file first (or waits until the oversize limit is reached) before scanning. The client must wait for the scanning to finish."
NEW QUESTION # 14
FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.
In this scenario, what are two requirements for the VLAN ID? (Choose two.)
- A. The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
- B. The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
- C. The two VLAN subinterfaces must have different VLAN IDs.
- D. The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.
Answer: C,D
Explanation:
https://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-use-emac-vlan-to-share-the-same-VLAN/ta-p/192843?externalID=FD43883 When FortiGate is operating in NAT mode, it means that it uses network address translation (NAT) to modify the source or destination IP addresses of the traffic passing through it1. NAT mode allows FortiGate to hide the IP addresses of the internal network from the external network, and to conserve IP addresses by using a single public IP address for multiple private IP addresses1.
A virtual LAN (VLAN) subinterface is a logical interface that allows traffic from different VLANs to enter and exit the FortiGate unit2. A VLAN subinterface is created by adding a VLAN ID to a physical interface or an aggregate interface2. A VLAN ID is a numerical identifier that distinguishes one VLAN from another2.
In this scenario, there are two requirements for the VLAN ID of the VLAN subinterfaces added to the same physical interface:
The two VLAN subinterfaces must have different VLAN IDs. This is because the VLAN ID is used to tag the traffic with the appropriate VLAN information, and to separate the traffic into different VLANs2. If the two VLAN subinterfaces have the same VLAN ID, they will not be able to distinguish the traffic from each other, and they will not be able to forward the traffic to the correct destination.
The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs. This is because VDOMs are virtual instances of FortiGate that can have their own interfaces, policies, and routing tables3. Each VDOM operates independently from other VDOMs, and can have its own VLAN subinterfaces with different or identical VLAN IDs3. However, this requires inter-VDOM links to allow traffic between different VDOMs3.
NEW QUESTION # 15
Which of the following statements is true regarding SSL VPN settings for an SSL VPN portal?
- A. By default, the admin GUI and SSL VPN portal use the same HTTPS port.
- B. By default, FortiGate uses WINS servers to resolve names.
- C. By default, the SSL VPN portal requires the installation of a client's certificate.
- D. By default, split tunneling is enabled.
Answer: A
NEW QUESTION # 16
FortiGuard categories can be overridden and defined in different categories. To create a web rating override for example.com home page, the override must be configured using a specific syntax.
Which two syntaxes are correct to configure web rating for the home page? (Choose two.)
- A. www.example.com
- B. example.com
- C. www.example.com:443
- D. www.example.com/index.html
Answer: A,B
Explanation:
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names - no URLs or wildcard characters are allowed.
OK: google.com or www.google.com
NO OK: www.google.com/index.html or google.*
FortiGate_Security_6.4 page 384
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names-- "no URLs or wildcard characters are allowed".
NEW QUESTION # 17
Which two actions can you perform only from the root FortiGate in a Security Fabric? (Choose two.)
- A. Log in to a downstream FortiSwitch device.
- B. Ban or unban compromised hosts.
- C. Shut down/reboot a downstream FortiGate device.
- D. Disable FortiAnalyzer logging for a downstream FortiGate device.
Answer: C,D
NEW QUESTION # 18
Which two types of traffic are managed only by the management VDOM? (Choose two.)
- A. DNS
- B. FortiGuard web filter queries
- C. PKI
- D. Traffic shaping
Answer: A,B
NEW QUESTION # 19
Which statement is correct regarding the use of application control for inspecting web applications?
- A. Application control does not display a replacement message for a blocked web application.
- B. Application control signatures are organized in a nonhierarchical structure.
- C. Application control can identity child and parent applications, and perform different actions on them.
- D. Application control does not require SSL inspection to identity web applications.
Answer: C
Explanation:
Application control is a feature that allows FortiGate to inspect and control the use of specific web applications on the network. When application control is enabled, FortiGate can identify child and parent applications, and can perform different actions on them based on the configuration.
NEW QUESTION # 20
Refer to the exhibits.
Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The administrator disabled the WebServer firewall policy.

Which IP address will be used to source NAT the traffic, if a user with address 10.0.1.10 connects over SSH to the host with address 10.200.3.1?
- A. 10.200.3.1
- B. 10.0.1.254
- C. 10.200.1.10
- D. 10.200.1.1
Answer: D
Explanation:
Traffic is coming from LAN to WAN, matches policy Full_Access which has NAT enable, so traffic uses source IP address of outgoing interface. Simple SNAT.
NEW QUESTION # 21
Refer to the exhibit, which contains a static route configuration.
An administrator created a static route for Amazon Web Services.
Which CLI command must the administrator use to view the route?
- A. get router info routing-table all
- B. get router info routing-table database
- C. get internet-service route list
- D. diagnose firewall proute list
Answer: D
Explanation:
ISDB static route will not create entry directly in routing-table. Reference: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Creating-a-static-route-for-Predefined-Internet/ta-p/198756 and here https://community.fortinet.com/t5/FortiGate/Technical-Tip-Verify-the-matching-policy-route/ta-p/190640 FortiGate Infrastructure 7.2 Study Guide (p.16 and p.59): "Even though they are configured as static routes, ISDB routes are actually policy routes and take precedence over any other routes in the routing table. As such, ISDB routes are added to the policy routing table." "FortiOS maintains a policy route table that you can view by running the diagnose firewall proute list command."
NEW QUESTION # 22
What is the primary FortiGate election process when the HA override setting is disabled?
- A. Connected monitored ports > Priority > System uptime > FortiGate serial number
- B. Connected monitored ports > System uptime > Priority > FortiGate serial number
- C. Connected monitored ports > HA uptime > Priority > FortiGate serial number
- D. Connected monitored ports > Priority > HA uptime > FortiGate serial number
Answer: C
NEW QUESTION # 23
Refer to the exhibit.
The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router.
When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.
Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?
- A. Configure a loopback interface with address 203.0.113.2/32.
- B. In the VIP configuration, enable arp-reply.
- C. In the firewall policy configuration, enable match-vip.
- D. Enable port forwarding on the server to map the external service port to the internal service port.
Answer: B
Explanation:
FortiGate Security 7.2 Study Guide (p.115): "Enabling ARP reply is usually not required in most networks because the routing tables on the adjacent devices contain the correct next hop information, so the networks are reachable. However, sometimes the routing configuration is not fully correct, and having ARP reply enabled can solve the issue for you. For this reason, it's a best practice to keep ARP reply enabled."
NEW QUESTION # 24
Which CLI command allows administrators to troubleshoot Layer 2 issues, such as an IP address conflict?
- A. get system performance status
- B. get system arp
- C. diagnose sys top
- D. get system status
Answer: B
Explanation:
"If you suspect that there is an IP address conflict, or that an IP has been assigned to the wrong device, you may need to look at the ARP table."
NEW QUESTION # 25
Refer to the exhibits.
Exhibit A shows the application sensor configuration. Exhibit B shows the Excessive-Bandwidth and Apple filter details.

Based on the configuration, what will happen to Apple FaceTime if there are only a few calls originating or incoming?
- A. Apple FaceTime will be allowed only if the Apple filter in Application and Filter Overrides is set to Allow.
- B. Apple FaceTime will be allowed, based on the Apple filter configuration.
- C. Apple FaceTime will be blocked, based on the Excessive-Bandwidth filter configuration.
- D. Apple FaceTime will be allowed, based on the Categories configuration.
Answer: C
Explanation:
FortiGate Security 7.2 Study Guide (p.310): "Then, FortiGate scans packets for matches, in this order, for the application control profile: 1. Application and filter overrides: If you have configured any application overrides or filter overrides, the application control profile considers those first. It looks for a matching override starting at the top of the list, like firewall policies. 2. Categories: Finally, the application control profile applies the action that you've configured for applications in your selected categories."
NEW QUESTION # 26
Refer to the exhibit.
Which contains a session diagnostic output. Which statement is true about the session diagnostic output?
- A. The session is in FIN_ACK state.
- B. The session is in ESTABLISHED state.
- C. The session is in FTN_WAIT state.
- D. The session is in SYN_SENT state.
Answer: D
Explanation:
Indicates TCP (proto=6) session in SYN_SENT state (proto=state=2) https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
NEW QUESTION # 27
Which statement about the deployment of the Security Fabric in a multi-VDOM environment is true?
- A. Each VDOM in the environment can be part of a different Security Fabric.
- B. VDOMs without ports with connected devices are not displayed in the topology.
- C. Downstream devices can connect to the upstream device from any of their VDOMs.
- D. Security rating reports can be run individually for each configured VDOM.
Answer: B
Explanation:
FortiGate Security 7.2 Study Guide (p.436): "When you configure FortiGate devices in multi-vdom mode and add them to the Security Fabric, each VDOM with its assigned ports is displayed when one or more devices are detected. Only the ports with discovered and connected devices appear in the Security Fabric view and, because of this, you must enable Device Detection on ports you want to have displayed in the Security Fabric. VDOMs without ports with connected devices are not displayed. All VDOMs configured must be part of a single Security Fabric."
NEW QUESTION # 28
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On Remote-FortiGate, set port2 as Interface.
- B. On HQ-FortiGate, set IKE mode to Main (ID protection).
- C. On HQ-FortiGate, disable Diffie-Helman group 2.
- D. On both FortiGate devices, set Dead Peer Detection to On Demand.
Answer: A,B
Explanation:
"In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: main, and aggressive mode. Settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel."
NEW QUESTION # 29
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)
- A. Antivirus in flow-based inspection
- B. Application control
- C. Web application firewall
- D. Web filter in flow-based inspection
- E. DNS filter
Answer: A,B,D
Explanation:
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/739623/dns-filter-handled-by-ips-engine-in-flow-mode
NEW QUESTION # 30
Refer to the exhibit.



The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200. 1. 1/24.
The LAN (port3) interface has the IP address 10.0. 1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0. 1. 10) pings the IP address of Remote-FortiGate (10.200.3. 1)?
- A. 10.200. 1. 1
- B. 10.200. 1.49
- C. 10.200. 1. 149
- D. 10.200. 1.99
Answer: D
NEW QUESTION # 31
Refer to the exhibit showing a debug flow output.
Which two statements about the debug flow output are correct? (Choose two.)
- A. The debug flow is of ICMP traffic.
- B. A firewall policy allowed the connection.
- C. The default route is required to receive a reply.
- D. A new traffic session is created.
Answer: A,D
NEW QUESTION # 32
An administrator has configured two-factor authentication to strengthen SSL VPN access. Which additional best practice can an administrator implement?
- A. Configure split tunneling in tunnel mode.
- B. Configure Source IP Pools.
- C. Configure host check .
- D. Configure different SSL VPN realms.
Answer: C
NEW QUESTION # 33
Refer to the exhibit.
Given the security fabric topology shown in the exhibit, which two statements are true? (Choose two.)
- A. There are five devices that are part of the security fabric.
- B. There are 19 security recommendations for the security fabric.
- C. This security fabric topology is a logical topology view.
- D. Device detection is disabled on all FortiGate devices.
Answer: B,C
Explanation:
Reference:
https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/761085/results
https://docs.fortinet.com/document/fortimanager/6.2.0/new-features/736125/security-fabric-topology
NEW QUESTION # 34
An administrator is configuring an Ipsec between site A and siteB. The Remotes Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192. 16. 1.0/24 and the remote quick mode selector is 192. 16.2.0/24. How must the administrator configure the local quick mode selector for site B?
- A. 192. 168.3.0/24
- B. 192. 168.2.0/24
- C. 192. 168. 1.0/24
- D. 192. 168.0.0/8
Answer: B
NEW QUESTION # 35
Which scanning technique on FortiGate can be enabled only on the CLI?
- A. Antivirus scan
- B. Heuristics scan
- C. Ransomware scan
- D. Trojan scan
Answer: B
NEW QUESTION # 36
View the exhibit.
Which of the following statements are correct? (Choose two.)
- A. The TunnelB route is the primary route for reaching the remote site. The TunnelA route is used only if the TunnelB VPN is down.
- B. This is a redundant IPsec setup.
- C. Dead peer detection must be disabled to support this type of IPsec setup.
- D. This setup requires at least two firewall policies with the action set to IPsec.
Answer: A,B
Explanation:
https://docs.fortinet.com/document/fortigate/6.2.4/cookbook/632796/ospf-with-ipsec-vpn-for-network-redundancy
NEW QUESTION # 37
......
SAP C_HRHFC_2311 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
Grab latest Amazon C_HRHFC_2311 Dumps as PDF Updated: https://passleader.realexamfree.com/C_HRHFC_2311-real-exam-dumps.html

