SNSA7
A custom carrier item can not be created on the SonicWall firewall.
-True
-False - ANS-False
A loopback NAT policy is needed when customers at the _____ community want to get entry to
an internal server through Public IP/DNS Name. (Select all that practice)
-WAN
-LAN
-DMZ
-WLAN - ANS--LAN
-DMZ
After the sso agent returns the user records, the firewall will question the configured
authentication server to acquire which of the following?
-institution club
-person important call
-distinguished names
-consumer login credentials - ANS-group membership
an get admission to rule precedence can be manually modifications or set by person.
-True
-False - ANS-True
Both HA Primary and Secondary firewalls may be managed in my view using the tracking IP
cope with.
True
False - ANS-True
Capture atp can not block a down load until a verdict is returned.
-True
-False - ANS-False
choose two strategies that sonicwall offers for dealing with global IPS and Anti-Spyware assault
threats.
-come across all
-signature groups
-prevent all
-log view - ANS--locate all
,-prevent all
classifiers in bandwidth control become aware of and prepare packets into traffic training by way
of matching unique standards.
True
False - ANS-True
DPI-SSL Client inspection should be enabled on the interface to experiment for encrypted trafic.
True
False - ANS-True
dpi-ssl examines ssl trafic, regardless of the port wide variety.
-True
-False - ANS-True
during which firewall configuration activity is it an amazing exercise to enable GAV,
anti-spyware, ips, and app control safety services?
-creating a bunch object
-developing a carrier item
-growing get admission to guidelines
-creating a sector - ANS-creating a area
allowing https user login is needed best for the virtual office portal; it isn't always neede for
netextender.
True
False - ANS-False
for what number of protocols is GAV inbound inspection enabled by default?
7
5
none
all - ANS-5
(through default 5
maximal available 7)
HA Primary and Secondary firewalls will habe distinctive settings.
-True
-False - ANS-False
become aware of a few quality practices related to applcontrol configuration. (Select all that
apply)
-distribute bandwidth utilization similarly across all applications
-enable logging, as needed, consistent with software
, -assign commonplace get right of entry to rules to all customers, irrespective of agencies
-fee-restrict software visitors - ANS--allow logging, as wished, according to application
-assign not unusual get entry to rules to all customers, no matter groups
if a network tracking policy is brought, what will be the reputation of the static routes while the
probe succeeds? (Select all that apply)
-the lower priority course might be disabled
-the firewall is unable to determine and generates an blunders message
-the lower precedence course will stay energetic
-the higher precedence direction will stay active - ANS--the lower priority route could be
disabled
-the higher priority path will stay active
if a sonicwall firewall administrator has to make common adjustments to networks taking part in
a website-to-web page VPN, which sort of vpn will be the fine choice?
-far off get right of entry to with gvc
-coverage- based vpn
-ssl-vpn
-faraway access with NetExtender
-tunnel interface vpn - ANS-tunnel interface vpn
if a consumer attempts to get right of entry to a internet site that has been blocked by means of
an organizational content material clear out rule, what type of default notification will the firewall
cause after logging the occasion in real-time?
-debug
-alert
-tell - ANS-alert
if the logging stage filter out is described as mistakes, which of the following alert types can also
be displayed inside the consequences? (Select all that observe)
-vital
-alert
-be aware
-emergency
-caution - ANS--critical
-alert
-emergency
In a VPN policy, local and Peer IKE IDs are obligatory.
True
False - ANS-False
in a VPN, it is advocated to permit the preserve alive on the remote side?
True
A custom carrier item can not be created on the SonicWall firewall.
-True
-False - ANS-False
A loopback NAT policy is needed when customers at the _____ community want to get entry to
an internal server through Public IP/DNS Name. (Select all that practice)
-WAN
-LAN
-DMZ
-WLAN - ANS--LAN
-DMZ
After the sso agent returns the user records, the firewall will question the configured
authentication server to acquire which of the following?
-institution club
-person important call
-distinguished names
-consumer login credentials - ANS-group membership
an get admission to rule precedence can be manually modifications or set by person.
-True
-False - ANS-True
Both HA Primary and Secondary firewalls may be managed in my view using the tracking IP
cope with.
True
False - ANS-True
Capture atp can not block a down load until a verdict is returned.
-True
-False - ANS-False
choose two strategies that sonicwall offers for dealing with global IPS and Anti-Spyware assault
threats.
-come across all
-signature groups
-prevent all
-log view - ANS--locate all
,-prevent all
classifiers in bandwidth control become aware of and prepare packets into traffic training by way
of matching unique standards.
True
False - ANS-True
DPI-SSL Client inspection should be enabled on the interface to experiment for encrypted trafic.
True
False - ANS-True
dpi-ssl examines ssl trafic, regardless of the port wide variety.
-True
-False - ANS-True
during which firewall configuration activity is it an amazing exercise to enable GAV,
anti-spyware, ips, and app control safety services?
-creating a bunch object
-developing a carrier item
-growing get admission to guidelines
-creating a sector - ANS-creating a area
allowing https user login is needed best for the virtual office portal; it isn't always neede for
netextender.
True
False - ANS-False
for what number of protocols is GAV inbound inspection enabled by default?
7
5
none
all - ANS-5
(through default 5
maximal available 7)
HA Primary and Secondary firewalls will habe distinctive settings.
-True
-False - ANS-False
become aware of a few quality practices related to applcontrol configuration. (Select all that
apply)
-distribute bandwidth utilization similarly across all applications
-enable logging, as needed, consistent with software
, -assign commonplace get right of entry to rules to all customers, irrespective of agencies
-fee-restrict software visitors - ANS--allow logging, as wished, according to application
-assign not unusual get entry to rules to all customers, no matter groups
if a network tracking policy is brought, what will be the reputation of the static routes while the
probe succeeds? (Select all that apply)
-the lower priority course might be disabled
-the firewall is unable to determine and generates an blunders message
-the lower precedence course will stay energetic
-the higher precedence direction will stay active - ANS--the lower priority route could be
disabled
-the higher priority path will stay active
if a sonicwall firewall administrator has to make common adjustments to networks taking part in
a website-to-web page VPN, which sort of vpn will be the fine choice?
-far off get right of entry to with gvc
-coverage- based vpn
-ssl-vpn
-faraway access with NetExtender
-tunnel interface vpn - ANS-tunnel interface vpn
if a consumer attempts to get right of entry to a internet site that has been blocked by means of
an organizational content material clear out rule, what type of default notification will the firewall
cause after logging the occasion in real-time?
-debug
-alert
-tell - ANS-alert
if the logging stage filter out is described as mistakes, which of the following alert types can also
be displayed inside the consequences? (Select all that observe)
-vital
-alert
-be aware
-emergency
-caution - ANS--critical
-alert
-emergency
In a VPN policy, local and Peer IKE IDs are obligatory.
True
False - ANS-False
in a VPN, it is advocated to permit the preserve alive on the remote side?
True