Watchguard Network Security Essentials
for Cloud-Managed Fireboxes
Which WatchGuard tools can you use to review the log messages generated by your
Firebox? (Select three) - answer Firebox System Manager > Traffic Monitor
Firewire XTM Web UI > Traffic Monitor
Dimension > Log manager
To enable remote devices to send log messages to Dimension through the gateway
Firebox, what must you verify is included in your gateway Firebox configuration? (Select
one.) - answer You must make sure that either the WG-Logging packet filter policy, or
another policy that allows external connections to Dimension over port 4115, is included
in the configuration file.
You have a privately addressed email server behind your Firebox. If you want to make
sure that all traffic from this server to the Internet appears to come from the public IP
address 203.0.113.25, regardless of policies, which from of NAT would you use?
(Select one.) - answerIn the SMTP policy that handles traffic from the email server,
select the option to apply dynamic NAT to all traffic in the policy and set the source IP
address 203.0.113.25
The IP address for the trusted interface on your Firebox is 10.0.40.1/24, but you want to
change the IP address for this interface. How can you avoid a network outage for clients
on the trusted network when you change the interface IP address to 10.0.50.1/24?
(Select one.) - answerAdd 10.0.40.1/24 as a secondary IP address for the interface
A user receives a deny message that the installation file (install.exe) is blocked by the
HTTP-proxy policy and cannot be downloaded. Which HTTP proxy action rule must you
modify to allow download of the installation file? (Select one.) - answerHTTP Response
> Body Content Types
How is a proxy policy different from a packet filter policy? (Select two.) - answerOnly a
proxy policy can prevent specific threats without blocking the entire connection
Only a proxy works ta the application, network, and transport layers to examine all
connection data
An email newsletter about sales from an external company is sometimes blocked by
spamBlocker. What option could you choose to make sure the newsletter is delivered to
for Cloud-Managed Fireboxes
Which WatchGuard tools can you use to review the log messages generated by your
Firebox? (Select three) - answer Firebox System Manager > Traffic Monitor
Firewire XTM Web UI > Traffic Monitor
Dimension > Log manager
To enable remote devices to send log messages to Dimension through the gateway
Firebox, what must you verify is included in your gateway Firebox configuration? (Select
one.) - answer You must make sure that either the WG-Logging packet filter policy, or
another policy that allows external connections to Dimension over port 4115, is included
in the configuration file.
You have a privately addressed email server behind your Firebox. If you want to make
sure that all traffic from this server to the Internet appears to come from the public IP
address 203.0.113.25, regardless of policies, which from of NAT would you use?
(Select one.) - answerIn the SMTP policy that handles traffic from the email server,
select the option to apply dynamic NAT to all traffic in the policy and set the source IP
address 203.0.113.25
The IP address for the trusted interface on your Firebox is 10.0.40.1/24, but you want to
change the IP address for this interface. How can you avoid a network outage for clients
on the trusted network when you change the interface IP address to 10.0.50.1/24?
(Select one.) - answerAdd 10.0.40.1/24 as a secondary IP address for the interface
A user receives a deny message that the installation file (install.exe) is blocked by the
HTTP-proxy policy and cannot be downloaded. Which HTTP proxy action rule must you
modify to allow download of the installation file? (Select one.) - answerHTTP Response
> Body Content Types
How is a proxy policy different from a packet filter policy? (Select two.) - answerOnly a
proxy policy can prevent specific threats without blocking the entire connection
Only a proxy works ta the application, network, and transport layers to examine all
connection data
An email newsletter about sales from an external company is sometimes blocked by
spamBlocker. What option could you choose to make sure the newsletter is delivered to