Network-Security-Essentials無料認定試験材料はこちらの60問題 [Q16-Q32]

Share

Network-Security-Essentials無料認定試験材料はこちらの60問題

リアルNetwork-Security-Essentialsは100%カバー率リアル試験問題を試そう!

質問 # 16
After you enable content inspection, your users see a certificate warning when they browse the Internet. What is one way to resolve this? (Select one.)

  • A. Install the current Firebox Proxy Authority certificate on your user workstations
  • B. Configure the HTTPS proxy policy to allow inbound traffic from your CA
  • C. Configure a WebBlocker exception for your certificate server
  • D. Import a trusted web server certificate to the Firebox

正解:A

解説:
When content inspection is enabled on a Firebox, it decrypts HTTPS traffic for inspection, which requires presenting its own certificate to the client devices. This often causes certificate warnings in web browsers because the certificate issued by the Firebox is not inherently trusted by the client browsers. To resolve this, you need to install the Firebox'sProxy Authority certificateon each user's workstation as a trusted certificate. This action will prevent browsers from displaying certificate warnings, as they will recognize the Firebox certificate as a trusted source for secure connections.


質問 # 17
Before packets are examined by Default Threat Protection, they are processed by firewall policies in top- down order.

  • A. False
  • B. True

正解:B

解説:
In Firebox configuration, packets are processed by firewall policies in atop-down orderbefore they reach Default Threat Protection. This ordering ensures that the firewall policies defined higher in the policy list take precedence. Packets are evaluated against each rule sequentially from top to bottom until a matching policy is found, which then determines the action taken (allow, deny, or inspect further). Only after this process will any unfiltered traffic be subject to Default Threat Protection for additional security checks.


質問 # 18
What steps must you take to send log messages from a Firebox to WatchGuard Cloud? (Select two.)

  • A. Define an Authentication Key that all your Fireboxes use to communicate with WatchGuard Cloud
  • B. Use the WatchGuard Cloud Add Device wizard to add the Firebox to WatchGuard Cloud
  • C. Configure Dimension to synchronize log messages with WatchGuard Cloud
  • D. Add the FQDN of your WatchGuard Cloud account as a Log Server on the Firebox
  • E. Enable WatchGuard Cloud in the Firebox configuration

正解:B、E

解説:
* Enable WatchGuard Cloud in Firebox Configuration: To send log messages to WatchGuard Cloud, you need to activate WatchGuard Cloud integration within the Firebox's configuration settings. This action prepares the device to communicate with WatchGuard Cloud and transfer log data.
* Use the WatchGuard Cloud Add Device Wizard: The Add Device wizard in WatchGuard Cloud is used to register and connect the Firebox to WatchGuard Cloud. This wizard guides administrators through the setup and ensures that the device is correctly configured to send logs and other data to the cloud.
These steps are required to establish connectivity and ensure that log messages are sent to WatchGuard Cloud.
Other options, such as adding an FQDN or configuring Dimension synchronization, are not necessary for this task.


質問 # 19
Match each WatchGuard Subscription Service with its function.

正解:

解説:

Explanation:
Here is the correct match for each WatchGuard Subscription Service and its function:
* A cloud-based service that uses emulation analysis to identify characteristics and behavior of malware : APT Blocker
* Uses artificial intelligence scanning on files to detect malicious software : IntelligentAV
* Uses signature-based file scanning to detect malicious software through Firebox proxy policies : Gateway AntiVirus
* Uses signatures to provide real-time protection against known software vulnerabilities : Intrusion Prevention Service
* Uses signatures to monitor and control use of applications on your network : Application Control
* Controls access to websites based on content categories : WebBlocker APT Blockeris a cloud-based, advanced threat detection service that performs behavioral analysis in a sandbox environment to identify sophisticated malware.
It focuses on identifying advanced persistent threats (APT) by observing their behavior in a controlled setting.
IntelligentAVleverages artificial intelligence to perform deep scanning and analysis of files to detect malware using predictive modeling techniques. This provides proactive protection by identifying previously unknown threats.
Gateway AntiVirusrelies on a signature-based detection mechanism to identify malware in real-time. It is used within Firebox's proxy policies to scan file transfers, ensuring files containing known malware are blocked.
Intrusion Prevention Service (IPS)scans network traffic against a database of known vulnerabilities to detect and prevent exploitation attempts in real time. It protects against network-based attacks targeting known vulnerabilities.
Application Controlhelps in monitoring, managing, and enforcing the use of applications across the network using a signature-based approach. It provides visibility and control over applications to enhance productivity and security.
WebBlockeris a content filtering service that restricts access to websites based on their content categories. It helps enforce web usage policies and block access to inappropriate or harmful content.


質問 # 20
You configured your Firebox interfaces and routes and want to verify the status of the routes and connected hosts. You found this information in Firebox System Manager > Status Report. What is true about the IPv4 routes and ARP table in this deployment? (Select one.)

  • A. The Firebox cannot resolve a MAC address for 10.0.1.32
  • B. 10.0.20.53 can be reached through the vlan20 interface
  • C. The MAC address for the default gateway that currently routes traffic is 00:50:56:b5:e5:42
  • D. The Firebox is publicly reachable at 198.51.100.1 through the eth0 interface
  • E. The MAC address for 172.16.1.20 is 00:50:56:b0:22:0f

正解:D

解説:
Analyzing the routing table and ARP table in the provided image:
* Routing Table Analysis:
* The route 0.0.0.0 with a gateway of 198.51.100.1 on the eth0 interface suggests this is the default route for outbound traffic, indicating that the Firebox's public interface (eth0) is configured to route traffic through this gateway.
* This confirms that the Firebox is publicly reachable at the IP address 198.51.100.1.
* ARP Table Analysis:
* The ARP entry for the gateway IP 198.51.100.1 is not directly shown in the image but could typically be resolved to verify connectivity.
* Other options provided, such as MAC address validation, do not correspond with the current ARP entries shown in the image.
This setup indicates that the Firebox is accessible publicly on the eth0 interface using the IP 198.51.100.1, makingOption Athe correct answer.


質問 # 21
There is an Internet outage at your primary ISP, but the Internet connection from the Firebox has not failed over to your backup ISP. Both ISP connectors are correctly cabled and have active physical links. What could cause this problem? (Select two.)

  • A. In the Multi-WAN settings, the Gradual Fallback option is enabled
  • B. In the Multi-WAN settings, the Immediate Fallback option is enabled
  • C. The Link Monitor target for the primary ISP interface is set to ping the default gateway, but the outage is further upstream
  • D. Link Monitor target for the backup ISP interface is not responding
  • E. The secondary IP addresses are not defined for the backup ISP interface

正解:C、D

解説:
* Link Monitor Target for Backup ISP: If the backup ISP's Link Monitor target is not responsive, the Firebox will not initiate a failover, as it interprets the backup connection as inactive or faulty.
* Primary ISP Link Monitor Configuration: When the Link Monitor for the primary ISP only checks the default gateway, it may not detect issues occurring further upstream. If the outage is beyond the gateway, failover will not activate because the monitor assumes the link is still valid.
These settings are critical to ensuring proper Multi-WAN failover behavior in case of ISP issues.


質問 # 22
What type of NAT enables clients on a private network to connect to servers on the Internet? (Select one.)

  • A. Hairpin NAT
  • B. NAT loopback
  • C. Static NAT
  • D. Dynamic NAT

正解:D

解説:
Dynamic NAT enables clients on a private network to connect to servers on the Internet. By translating private IP addresses to a public IP address (or pool of addresses), Dynamic NAT allows multiple devices within a private network to access external resources on the Internet. This form of NAT is essential in conserving IP addresses and maintaining privacy for internal network topologies.


質問 # 23
You recently installed network monitoring software on your server and then performed a port scan for each IP address in the network. When the scan finishes, you notice that the server lost access to the Internet. What is the most likely cause of this issue? (Select one.)

  • A. The policy that handles outbound traffic was automatically disabled because the Firebox was port scanned
  • B. The server IP address was added to the Blocked Sites list because the network was flooded with ESP traffic during the port scan
  • C. The server IP address was added to the Blocked Sites list because of the default packet handling port scan rule
  • D. The port scan traffic matched a default HTTP proxy content type rule configured with a Block action
  • E. The server IP address was added to the Blocked Sites list because an IPS signature was matchedduring the port scan

正解:C

解説:
When a port scan is detected, Firebox devices with default settings often include a rule to add the source IP address of the scan to the Blocked Sites list to prevent potential threats. This is a standard security measure in Firebox configurations, aimed at mitigating the risk of network scanning attempts. Consequently, if the server you used to perform the port scan was added to the Blocked Sites list, it would lose Internet access as the device blocks any outgoing connections from that IP. This behavior aligns with Firebox's handling of port scan detection through default security rules.


質問 # 24
Your users have no network connectivity on their computers in the 10.0.40.0/24 network. You investigate and discover the DHCP address pool for this network is exhausted, but there are no available IP addresses in the network to assign. Which of these options can you use to expand the IP address space of this network? (Select two.)

  • A. Create a Dynamic NAT rule for traffic from the 10.0.40.1/24 network going to the 10.0.50.1/24 network
  • B. Change the IP address of the 10.0.40.1/24 network to 10.0.40.123/24
  • C. Enable a wireless SSID for the 10.0.40.1/24 network
  • D. Add 10.0.50.1/24 to the 10.0.40.1/24 network as a secondary network
  • E. Bridge the 10.0.40.1/24 network across additional interfaces

正解:D、E

解説:
* Adding a Secondary Network (10.0.50.1/24): By adding a secondary subnet (such as10.0.50.1/24) to the existing 10.0.40.1/24 network, you expand the IP address space, effectively increasing the number of available IP addresses for DHCP allocation.
* Bridging Across Additional Interfaces: Bridging the 10.0.40.1/24 network across multiple interfaces can also increase the available address pool by creating a larger logical network. This approach helps manage IP space across a broader range of devices without subnet fragmentation.
These methods provide scalable solutions to expand IP address availability within constrained network spaces.


質問 # 25
You enable a network device monitoring application on a server with IP address 10.0.1.22. After you run the application, it reports that it cannot ping the Firebox at 10.0.1.1, and you see this log message in Traffic Monitor. What is the most likely cause of this issue? (Select one.)

  • A. The dynamic NAT statement is not configured correctly for the 10.0.1.0/24 subnet
  • B. There is no route on the Firebox for the 10.0.1.0/24 subnet
  • C. The default Unhandled Internal Packet policy is at the top of the policy set
  • D. The server IP address is on the Blocked Sites list
  • E. There is no policy that allows Ping traffic from the server to the Firebox alias

正解:E

解説:
The most likely reason for the network device monitoring application's failure to ping the Firebox is the absence of an explicit policy permitting Ping traffic from the server (IP 10.0.1.22) to the Firebox alias (10.0.1.1). By default, Firebox policies are configured to allow only traffic explicitly permitted by a policy.
Therefore, without a dedicated policy allowing ICMP (Ping) requests from this specific source to the Firebox, the device will drop the traffic, resulting in a connectivity failure for Ping.
This is a common scenario in Firebox configurations, where restrictive policy settings enhance network security by blocking all traffic types unless specifically allowed.


質問 # 26
In Firebox System Manager, where can you perform each of these tasks?

正解:

解説:

Explanation:
Here are the correct answers based on the Firebox System Manager interface functions:
* See the routing table and interface statisticsanswer:Firebox System Manager - Status Report Explanation: The Status Report section in Firebox System Manager includes information on network routing and interface statistics, providing insights into network paths and interface performance.
* See a list of users connected to the Fireboxanswer:Firebox System Manager - Authentication List Explanation: The Authentication List displays all active user sessions connected to the Firebox, showing authenticated users and their session details.
* Learn the status of your IPS signature databaseanswer:Firebox System Manager - Subscription Services Explanation: Subscription Services in FSM gives information on the status of services like IPS, showing the update status and version of the signature database.
* Ping the source of a denied packetanswer:Firebox System Manager - Traffic Monitor Explanation: The Traffic Monitor tool allows administrators to track packet details and offers functionality to ping sources directly, aiding in network troubleshooting.
* Block all traffic for an IP addressanswer:Firebox System Manager - Blocked Sites List Explanation: The Blocked Sites List feature in FSM lets administrators add IP addresses to a blacklist, blocking all incoming and outgoing traffic for specified addresses.
These answers utilize standard Firebox management features for performing administrative and diagnostic tasks efficiently. Let me know if you need further assistance with Firebox System Manager capabilities.


質問 # 27
When Mobile VPN is enabled, remote users receive the domain name and DNS servers from the Firebox Network Configuration by default.

  • A. False
  • B. True

正解:B

解説:
WhenMobile VPNis enabled on a Firebox, remote users receive network configuration settings, including domain nameandDNS server informationfrom the Firebox by default. This setupensures that remote users can resolve internal domain names and access network resources as though they were connected directly to the internal network. This functionality is essential for maintaining consistent user experience and connectivity while working remotely.


質問 # 28
You configured your Firebox as a DHCP server and want to verify the status of the leased addresses. You found this information in Firebox System Manager > Status Report. What is true about DHCP leases in this deployment? (Select two.)

  • A. The hostname Server1 is associated with the IP address 10.20.1.100
  • B. 252 IP addresses are currently available in the address pool for the 10.0.1.0/24 network
  • C. The MAC address for the host using 10.0.1.2 is 00:50:56:9a:75
  • D. DHCP leases for the 10.20.1.0/24 network are valid for 24 hours
  • E. DHCP leases for the 10.0.1.0/24 network are valid for 8 hours

正解:B、E

解説:
Analyzing the DHCP lease information from the provided image:
* Lease Duration for 10.0.1.0/24 Network:
* The lease for IP address 10.0.1.2 on interface eth1 starts at 2023/03/09 21:42:33 and ends at 2023
/03/10 05:42:33, showing a lease duration of 8 hours. Thus, DHCP leases for the 10.0.1.0/24 network are set to be valid for 8 hours.
* Available IP Addresses in 10.0.1.0/24 Pool:
* The summary indicates that 1 out of 253 IPs is leased for the 10.0.1.0/24 subnet, meaning 252 IPs remain available in the address pool.
These details confirm the correct answers:BandD.
Other options, such as MAC address and hostname associations, do not match the data provided in the image, making them incorrect choices. Let me know if you need further assistance analyzing DHCP configurations on Firebox devices.


質問 # 29
If the Firebox does not have a feature key installed, which of these statements are true? (Select three.)

  • A. You cannot upgrade the Firebox
  • B. You cannot configure subscription services
  • C. You cannot save configuration changes to the Firebox
  • D. Only one user can connect to the Internet through the Firebox
  • E. You cannot run the Web Setup Wizard

正解:A、B、C

解説:
Without a feature key:
* Option A: Upgrades are restricted, as the device relies on the feature key to validate software entitlement.
* Option B: Subscription services like antivirus, IPS, or web filtering cannot be configured without the feature key, which activates these services.
* Option D: Configuration changes cannot be permanently saved to the Firebox without the feature key, limiting the device's functionality.
* Option C(Web Setup Wizard) andOption E(one user internet access) do not depend on the feature key and are not restricted in this scenario.


質問 # 30
Match each type of NAT with the correct descriptor

正解:

解説:

Explanation:

Here are the correct answers for matching each NAT type with its descriptor:
* Changes incoming packets sent to a public IP address to different internal IP addresses based on the destination portanswer:Static NAT Explanation: Static NAT maps a public IP address to multiple internal IP addresses based on the port, allowing specific services or applications to be routed to various internal destinations.
* Allows a user on the trusted or optional network to connect to a public server that is on the same physical Firebox interface by its public IP address or domain nameanswer:NAT loopback Explanation: NAT loopback (or NAT reflection) allows internal users to access a public IP address or domain name that resolves to the same local network, making it appear as if they are connecting from outside the network.
* Conserves IP addresses and hides the internal topology of your networkanswer:Dynamic NAT Explanation: Dynamic NAT (or PAT - Port Address Translation) conserves public IP addresses by allowing multiple internal devices to share a single public IP address. This setup is commonly used for outbound internet connections from a private network.
* Changes all incoming and outgoing packets sent from one range of addresses to a different range of addressesanswer:1-to-1 NAT Explanation: 1-to-1 NAT maps each internal IP address to a unique public IP address, providing a one-to-one relationship. This type of NAT is often used for networks that require external access to specific internal resources.


質問 # 31
Which of these options are private IPv4 address spaces described in RFC 1918 Address Allocation for Private Internets? (Select three.)

  • A. 10.0.0.0/8
  • B. 172.16.0.0/12
  • C. 172.0.0.0/16
  • D. 102.0.2.0/24
  • E. 192.168.0.0/16

正解:A、B、E

解説:
RFC 1918 defines private IP address spaces that are not routable on the public internet and are reserved for internal network use:
* 10.0.0.0/8: Covers IP addresses from 10.0.0.0 to 10.255.255.255 and is often used in large private networks.
* 172.16.0.0/12: Covers addresses from 172.16.0.0 to 172.31.255.255 and is commonly used in medium- sized networks.
* 192.168.0.0/16: Covers addresses from 192.168.0.0 to 192.168.255.255 and is frequently used in small to medium networks, especially for home and office routers.
* Option C(102.0.2.0/24) andOption D(172.0.0.0/16) are not private address spaces according to RFC
1918.


質問 # 32
......

Network-Security-Essentials試験問題集簡単なまとめ:https://www.goshiken.com/WatchGuard/Network-Security-Essentials-mondaishu.html

Network-Security-Essentials最新Locally-Managed Fireboxesトレーニングと認定をゲット:https://drive.google.com/open?id=1uYx1x6n7RzmwWvh4pybZy-z6DkWjMS_p