WatchGuard Exam
Intrusion Protection Server (IPS) - answer Uses Signatures to provide real-time
protection against network attacks.
Only 50 clients on the trusted network of your firebox can connect to the internet at the
same time. What could cause this? - answer The DHCP address pool on the trusted
interface has only 50 ip addresses.
From the Firewire Web UI, you can generate a report that shows yoru device
configuration settings. (True of False) - answer True
To use the Web Setup Wizard or Quick Setup Wizard to configure your Firebox or XTM
device, your computer must have an IP address on which subnet? - answer10.0.1.0/24
APT Blocker - answerUses full-system emulation analysis to identify characteristics and
behavior of zero-day malware.
If you disable the Outgoing policy, which policies must you add to allow trusted users to
connect to commonly used websites? - answerHTTP port 80 , HTTPS port 443 , DNS
port 53
To enable remote devices to send log messages to Dimension through the gateway
Firebox, what must you verify is included in your gateway Firebox configuration? -
answerYou must add a policy to the remote device configuration file to allow traffic to a
Dimension.
Which takes precedence: WebBlocker category match or a WebBlocker exception? -
answerWebBlocker category match
Which of these actions adds a host to the temporary or permanent blocked sites list?
A.Enable theAUTO-block sites that attempt to connectoption in a deny policy.
B.Add the site to theBlocked Sites Exceptionslist.
C.On the Firebox System Manager >Blocked Sitestab, selectAdd.
D.In Policy Manager, selectSetup> Default Threat Protection > Blocked Sitesand
clickAdd. - answerA,C,D
What settings must your device configuration file include for Gateway AntiVirus to
protect users on your network? - answerConfigure a policy to use a proxy action that
has AntiVirus settings configured.
Configure Gateway AntiVirus settings for a proxy action.
, You can configure your Firebox to automatically redirect users to the Authentication
Portal page.
(True or False) - answerTrue
Application Control - answerManages use of applications on your network.
How can you include log messages from more than one Firebox in a single report
generated by Dimension? - answerCreate a device group and view the reports for that
group.
Create a report schedule that includes all the devices you want to include in the report.
In the default Firebox configuration file, which policies control management access to
the device? - answerWatchGuard
WatchGuard Web UI
Which tool can ping the source of a denied packet? - answerTraffic Monitor
Which authentication servers can you use with your Firebox?
A.Active Directory
B.RADIUS
C.LDAP
D.Linux Authentication
E.Kerberos
F.TACACS+
G.Firebox databases - answerA,B,C,G
In a Mobile VPN configuration, why would you choose default route VPN over split
tunnel VPN? - answerDefault route VPN allows your Firebox to examine all remote user
traffic
What is the best method to downgrade the version of Fireware OS on your Firebox
without losing all device configuration settings? - answerRestore a saved backup image
that was created for thedevice before the last Fireware OS upgrade.
The policies in a default Firebox configuration do not allow outgoing traffic from optional
interfaces. (True or False) - answerFalse
You need to create an HTTP-proxy policy to a specific domain for software updates
(example.com). The update site has multiple subdomains and dynamic IP addresses on
a content delivery network. Which of these options is the best way to define the
destination in your HTTPproxy policy? - answerConfigure an FQDN for*.example.com.
Which policies can use the Intrusion Prevention Service to block network attacks? -
answerOnly proxy policies
Intrusion Protection Server (IPS) - answer Uses Signatures to provide real-time
protection against network attacks.
Only 50 clients on the trusted network of your firebox can connect to the internet at the
same time. What could cause this? - answer The DHCP address pool on the trusted
interface has only 50 ip addresses.
From the Firewire Web UI, you can generate a report that shows yoru device
configuration settings. (True of False) - answer True
To use the Web Setup Wizard or Quick Setup Wizard to configure your Firebox or XTM
device, your computer must have an IP address on which subnet? - answer10.0.1.0/24
APT Blocker - answerUses full-system emulation analysis to identify characteristics and
behavior of zero-day malware.
If you disable the Outgoing policy, which policies must you add to allow trusted users to
connect to commonly used websites? - answerHTTP port 80 , HTTPS port 443 , DNS
port 53
To enable remote devices to send log messages to Dimension through the gateway
Firebox, what must you verify is included in your gateway Firebox configuration? -
answerYou must add a policy to the remote device configuration file to allow traffic to a
Dimension.
Which takes precedence: WebBlocker category match or a WebBlocker exception? -
answerWebBlocker category match
Which of these actions adds a host to the temporary or permanent blocked sites list?
A.Enable theAUTO-block sites that attempt to connectoption in a deny policy.
B.Add the site to theBlocked Sites Exceptionslist.
C.On the Firebox System Manager >Blocked Sitestab, selectAdd.
D.In Policy Manager, selectSetup> Default Threat Protection > Blocked Sitesand
clickAdd. - answerA,C,D
What settings must your device configuration file include for Gateway AntiVirus to
protect users on your network? - answerConfigure a policy to use a proxy action that
has AntiVirus settings configured.
Configure Gateway AntiVirus settings for a proxy action.
, You can configure your Firebox to automatically redirect users to the Authentication
Portal page.
(True or False) - answerTrue
Application Control - answerManages use of applications on your network.
How can you include log messages from more than one Firebox in a single report
generated by Dimension? - answerCreate a device group and view the reports for that
group.
Create a report schedule that includes all the devices you want to include in the report.
In the default Firebox configuration file, which policies control management access to
the device? - answerWatchGuard
WatchGuard Web UI
Which tool can ping the source of a denied packet? - answerTraffic Monitor
Which authentication servers can you use with your Firebox?
A.Active Directory
B.RADIUS
C.LDAP
D.Linux Authentication
E.Kerberos
F.TACACS+
G.Firebox databases - answerA,B,C,G
In a Mobile VPN configuration, why would you choose default route VPN over split
tunnel VPN? - answerDefault route VPN allows your Firebox to examine all remote user
traffic
What is the best method to downgrade the version of Fireware OS on your Firebox
without losing all device configuration settings? - answerRestore a saved backup image
that was created for thedevice before the last Fireware OS upgrade.
The policies in a default Firebox configuration do not allow outgoing traffic from optional
interfaces. (True or False) - answerFalse
You need to create an HTTP-proxy policy to a specific domain for software updates
(example.com). The update site has multiple subdomains and dynamic IP addresses on
a content delivery network. Which of these options is the best way to define the
destination in your HTTPproxy policy? - answerConfigure an FQDN for*.example.com.
Which policies can use the Intrusion Prevention Service to block network attacks? -
answerOnly proxy policies