[2024年08月]更新のSAP C-HRHFC-2311問題集厳選された問題集でパスして、最短時間を目指そう
SAP C-HRHFC-2311試験問題集で[2024年最新] 練習 高合格率な試験問題集問題
SAP C-HRHFC-2311 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
質問 # 80
Refer to the exhibit.

The exhibit contains the configuration for an SD-WAN Performance SLA, as well as the output of diagnose sys virtual-wan-link health-check . Which interface will be selected as an outgoing interface?
- A. port2
- B. port1
- C. port4
- D. port3
正解:B
解説:
Port 1 shows the lowest latency.
質問 # 81
What are two functions of the ZTNA rule? (Choose two.)
- A. It applies security profiles to protect traffic.
- B. It defines the access proxy.
- C. It enforces access control.
- D. It redirects the client request to the access proxy.
正解:A、C
解説:
A ZTNA rule is a policy that enforces access control and applies security profiles to protect traffic between the client and the access proxy1. A ZTNA rule defines the following parameters1:
Incoming interface: The interface that receives the client request.
Source: The address and user group of the client.
ZTNA tag: The tag that identifies the domain that the client belongs to.
ZTNA server: The server that hosts the access proxy.
Destination: The address of the application that the client wants to access.
Action: The action to take for the traffic that matches the rule. It can be accept, deny, or redirect.
Security profiles: The security features to apply to the traffic, such as antivirus, web filter, application control, and so on.
A ZTNA rule does not redirect the client request to the access proxy. That is the function of a policy route that matches the ZTNA tag and sends the traffic to the ZTNA server2.
A ZTNA rule does not define the access proxy. That is done by creating a ZTNA server object that specifies the IP address, port, and certificate of the access proxy3.
FortiGate Infrastructure 7.2 Study Guide (p.177): "A ZTNA rule is a proxy policy used to enforce access control. You can define ZTNA tags or tag groups to enforce zero-trust role-based access. To create a rule, type a rule name, and add IP addresses and ZTNA tags or tag groups that are allowed or blocked access. You also select the ZTNA server as the destination. You can also apply security profiles to protect this traffic."
質問 # 82
An administrator is configuring an Ipsec between site A and siteB. The Remotes Gateway setting in both sites has been configured as Static IP Address. For site A, the local quick mode selector is 192. 16. 1.0/24 and the remote quick mode selector is 192. 16.2.0/24. How must the administrator configure the local quick mode selector for site B?
- A. 192. 168.3.0/24
- B. 192. 168. 1.0/24
- C. 192. 168.0.0/8
- D. 192. 168.2.0/24
正解:D
質問 # 83
How does FortiGate act when using SSL VPN in web mode?
- A. FortiGate acts as an HTTP reverse proxy.
- B. FortiGate acts as an FDS server.
- C. FortiGate acts as DNS server.
- D. FortiGate acts as router.
正解:A
解説:
Reference:
https://pub.kb.fortinet.com/ksmcontent/Fortinet-Public/current/Fortigate_v4.0MR3/fortigate-sslvpn-40-mr3.pdf
質問 # 84
Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)
- A. ping
- B. udp-echo
- C. TWAMP
- D. DNS
正解:B、C
質問 # 85
Examine this PAC file configuration.
Which of the following statements are true? (Choose two.)
- A. Browsers can be configured to retrieve this PAC file from the FortiGate.
- B. Any web request to the 172.25. 120.0/24 subnet is allowed to bypass the proxy.
- C. Any web request fortinet.com is allowed to bypass the proxy.
- D. All requests not made to Fortinet.com or the 172.25. 120.0/24 subnet, have to go through altproxy.corp.com: 8060.
正解:A、C
質問 # 86
51 Which statement is correct regarding the inspection of some of the services available by web applications embedded in third-party websites?
- A. The security actions applied on the web applications will also be explicitly applied on the third-party websites.
- B. The application signature database inspects traffic only from the original web application server.
- C. FortiGuard maintains only one signature of each web application that is unique.
- D. FortiGate can inspect sub-application traffic regardless where it was originated.
正解:D
解説:
Reference:
https://help.fortinet.com/fortiproxy/11/Content/Admin%20Guides/FPX-AdminGuide/300_System/303d_FortiG
質問 # 87
Refer to the exhibit, which contains a session diagnostic output.
Which statement is true about the session diagnostic output?
- A. The session is a bidirectional TCP connection.
- B. The session is a UDP unidirectional state.
- C. The session is a bidirectional UDP connection.
- D. The session is in TCP ESTABLISHED state.
正解:C
解説:
https://kb.fortinet.com/kb/viewContent.do?externalId=FD30042
質問 # 88
A network administrator has enabled full SSL inspection and web filtering on FortiGate. When visiting any HTTPS websites, the browser reports certificate warning errors. When visiting HTTP websites, the browser does not report errors.
What is the reason for the certificate warning errors?
- A. The full SSL inspection feature does not have a valid license.
- B. The certificate used by FortiGate for SSL inspection does not contain the required certificate extensions.
- C. The matching firewall policy is set to proxy inspection mode.
- D. The browser does not trust the certificate used by FortiGate for SSL inspection.
正解:D
解説:
FortiGate Security 7.2 Study Guide (p.235): "If FortiGate receives a trusted SSL certificate, then it generates a temporary certificate signed by the built-in Fortinet_CA_SSL certificate and sends it to the browser. If the browser trusts the Fortinet_CA_SSL certificate, the browser completes the SSL handshake. Otherwise, the browser also presents a warning message informing the user that the site is untrusted. In other words, for this function to work as intended, you must import the Fortinet_CA_SSL certificate into the trusted root CA certificate store of your browser."
質問 # 89
Which three statements are true regarding session-based authentication? (Choose three.)
- A. It requires more resources.
- B. It can differentiate among multiple clients behind the same source IP address.
- C. IP sessions from the same source IP address are treated as a single user.
- D. HTTP sessions are treated as a single user.
- E. It is not recommended if multiple users are behind the source NAT
正解:A、B、D
質問 # 90
Refer to the exhibits.

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).
What must the administrator do to synchronize the address object?
- A. Change the csf setting on both devices to set downstream-access enable.
- B. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
- C. Change the csf setting on ISFW (downstream) to set configuration-sync local.
- D. Change the csf setting on ISFW (downstream) to set authorization-request-type certificate.
正解:A
質問 # 91
Refer to the exhibits.

The SSL VPN connection fails when a user attempts to connect to it. What should the user do to successfully connect to SSL VPN?
- A. Change the SSL VPN portal to the tunnel.
- B. Change the SSL VPN port on the client.
- C. Change the idle-timeout.
- D. Change the Server IP address.
正解:B
質問 # 92
Refer to the exhibit.



The exhibit contains a network diagram, central SNAT policy, and IP pool configuration.
The WAN (port1) interface has the IP address 10.200. 1. 1/24.
The LAN (port3) interface has the IP address 10.0. 1.254/24.
A firewall policy is configured to allow to destinations from LAN (port3) to WAN (port1).
Central NAT is enabled, so NAT settings from matching Central SNAT policies will be applied.
Which IP address will be used to source NAT the traffic, if the user on Local-Client (10.0. 1. 10) pings the IP address of Remote-FortiGate (10.200.3. 1)?
- A. 10.200. 1. 149
- B. 10.200. 1.49
- C. 10.200. 1.99
- D. 10.200. 1. 1
正解:C
質問 # 93
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?
- A. Add user accounts to the Ignore User List.
- B. Add user accounts to the FortiGate group fitter.
- C. Add user accounts to Active Directory (AD).
- D. Add the support of NTLM authentication.
正解:A
質問 # 94
A network administrator is troubleshooting an IPsec tunnel between two FortiGate devices. The administrator has determined that phase 1 fails to come up. The administrator has also re-entered the pre-shared key on both FortiGate devices to make sure they match.
Based on the phase 1 configuration and the diagram shown in the exhibit, which two configuration changes will bring phase 1 up? (Choose two.)
- A. On Remote-FortiGate, set port2 as Interface.
- B. On HQ-FortiGate, set IKE mode to Main (ID protection).
- C. On HQ-FortiGate, disable Diffie-Helman group 2.
- D. On both FortiGate devices, set Dead Peer Detection to On Demand.
正解:A、B
解説:
"In IKEv1, there are two possible modes in which the IKE SA negotiation can take place: main, and aggressive mode. Settings on both ends must agree; otherwise, phase 1 negotiation fails and both IPsec peers are not able to establish a secure channel."
質問 # 95
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)
- A. The subject alternative name (SAN) field in the server certificate
- B. The serial number in the server certificate
- C. The server name indication (SNI) extension in the client hello message
- D. The subject field in the server certificate
- E. The host field in the HTTP header
正解:A、C、D
解説:
A) The server name indication (SNI) extension in the client hello message. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The SNI extension is a feature of the TLS protocol that allows a client to indicate the hostname of the server it wants to connect to during the TLS handshake. This helps the server to present the appropriate certificate for the requested hostname, especially when the server hosts multiple domains on the same IP address1. FortiGate can use the SNI extension in the client hello message to identify the hostname of the SSL server and verify it against the server certificate2.
B) The subject alternative name (SAN) field in the server certificate. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The SAN field is an extension of the X.509 certificate standard that allows a certificate to specify multiple hostnames or IP addresses that are valid for the certificate. This helps the certificate to support multiple domains or subdomains on the same server, or multiple servers with different IP addresses3. FortiGate can use the SAN field in the server certificate to identify the hostname of the SSL server and verify it against the client request2.
E) The subject field in the server certificate. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The subject field is a part of the X.509 certificate standard that contains information about the identity of the entity that owns the certificate, such as common name, organization, country, and so on. The common name usually specifies the hostname or domain name of the server that owns the certificate4. FortiGate can use the subject field in the server certificate to identify the hostname of the SSL server and verify it against the client request2.
質問 # 96
Which two types of traffic are managed only by the management VDOM? (Choose two.)
- A. Traffic shaping
- B. FortiGuard web filter queries
- C. DNS
- D. PKI
正解:B、C
質問 # 97
Refer to the exhibit.
Refer to the web filter raw logs.
Based on the raw logs shown in the exhibit, which statement is correct?
- A. The action on firewall policy ID 1 is set to warning.
- B. Social networking web filter category is configured with the action set to authenticate.
- C. Access to the social networking web filter category was explicitly blocked to all users.
- D. The name of the firewall policy is all_users_web.
正解:B
質問 # 98
FortiGuard categories can be overridden and defined in different categories. To create a web rating override for example.com home page, the override must be configured using a specific syntax.
Which two syntaxes are correct to configure web rating for the home page? (Choose two.)
- A. www.example.com:443
- B. www.example.com
- C. example.com
- D. www.example.com/index.html
正解:B、C
解説:
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names - no URLs or wildcard characters are allowed.
OK: google.com or www.google.com
NO OK: www.google.com/index.html or google.*
FortiGate_Security_6.4 page 384
When using FortiGuard category filtering to allow or block access to a website, one option is to make a web rating override and define the website in a different category. Web ratings are only for host names-- "no URLs or wildcard characters are allowed".
質問 # 99
By default, FortiGate is configured to use HTTPS when performing live web filtering with FortiGuard servers.
Which CLI command will cause FortiGate to use an unreliable protocol to communicate with FortiGuard servers for live web filtering?
- A. set protocol tcp
- B. set fortiguard-anycast disable
- C. set webfilter-force-off disable
- D. set webfilter-cache disable
正解:B
解説:
y default, "fortiguard-anycast" is enabled, and this setting only works with "set protocol https". To use udp (ie. "set protocol udp"), "fortiguard-anycast" must be disabled.
Reference:
"By default, FortiGate is configured to enforce the use of HTTPS port 443 to perform live filtering with FortiGuard or FortiManager. Other ports and protocols are available by disabling the FortiGuard anycast setting on the CLI."
質問 # 100
An administrator has configured the following settings:
What are the two results of this configuration? (Choose two.)
- A. Device detection on all interfaces is enforced for 30 minutes.
- B. A session for denied traffic is created.
- C. The number of logs generated by denied traffic is reduced.
- D. Denied users are blocked for 30 minutes.
正解:B、C
解説:
ses-denied-traffic
Enable/disable including denied session in the session table.
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/20620/config-system-settings block-session-timer Duration in seconds for blocked sessions .
integer
Minimum value: 1 Maximum value: 300
30
https://docs.fortinet.com/document/fortigate/7.0.6/cli-reference/1620/config-system-global
質問 # 101
Examine the exhibit, which contains a virtual IP and firewall policy configuration.

The WAN (port1) interface has the IP address 10.200. 1. 1/24. The LAN (port2) interface has the IP address 10.0. 1.254/24.
The first firewall policy has NAT enabled on the outgoing interface address. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT the Internet traffic coming from a workstation with the IP address 10.0. 1. 10/24?
- A. 10.0. 1.254
- B. 10.200. 1. 1
- C. 10.200. 1. 10
- D. Any available IP address in the WAN (port1) subnet 10.200. 1.0/24
正解:C
解説:
https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-firewall-52/Firewall%20Objects/Virtual%20IPs.
質問 # 102
......
C-HRHFC-2311試験問題集でPDF合格保証 成功は正確かつ更新された問題:https://www.passtest.jp/SAP/C-HRHFC-2311-shiken.html
C-HRHFC-2311問題集-[最新2024]SAP試験問題集を掴み取れ:https://drive.google.com/open?id=1tMYL8kWfEJW1FA5aKr3jK46EU5Z4l_O-