Watchguard Network Security Essentials
(Exam Questions 2021), WatchGuard
Network Security Essentials with 100%
Correct Solutions
***You configured four Device Administrator user accounts for your Firebox. To see
a report of which Device Management users have made changes to the device
configuration, what must you do? (Select two.)
A. Start Firebox System Manager for the device and review the activity for the
Management Users on the Authentication List tab.
B. Connect to Report Manager or Dimension and view the Audit Trail report for
your device.
C. Open WatchGuard Server Center and review the configuration history for
managed devices.
D. Configure your device to send audit trail log messages to your WatchGuard Log
Server or Dimension Log Server. - ANSWER Connect to Report Manager or
Dimension and view the Audit Trail report for your device.
Open WatchGuard Server Center and review the configuration history for
managed devices.
***Which items are included in a Firebox backup image file? (Select four.)
A. Support snapshot
,B. Fireware OS
C. Configuration file
D. Log file
E. Feature keys
F. Certificates
G. Passwords
This question was on the exam but it had different answers.
One of the answer options was policies. I don't believe feature keys was on there.
Also users and roles were on there. - ANSWER Configuration file
Certificates
Passwords
Feature key
***Only 50 clients on the trusted network of your Firebox can connect to the Internet at
the same time. What could cause this? (Select one.)
A. The Live Security feature key is expired.
B. The device feature key allows a maximum of 50 client connections.
C. The DHCP address pool on the trusted interface has only 50 IP addresses.
D. The Outgoing policy allows a maximum of 50 client connections. - ANSWER The DHCP
address pool on the trusted interface has only 50 IP addresses.
Route to 10.0.20.0/24, Gateway 10.0.2.254 - ANSWER Clients on the trusted
network need to connect to a server behind a router on the optional network. Based
on this image, what static route must be added to the Firebox for traffic from clients
on the trusted network to reach a server at 10.0.20.100? (Select one.)
,A. Route to 10.0.20.0/24, Gateway 10.0.2.1
B. Route to 10.0.20.0/24, Gateway 10.0.2.254
C. Route to 10.0.20.0, Gateway 10.0.2.254
D. Route to 10.0.10.0/24, Gateway 10.0.10.1
***The IP address for the trusted interface on your Firebox is 10.0.40.1/24, but you
want to change the IP address for this interface. How can you avoid a network
outage for clients on the trusted network when you change the interface IP address
to 10.0.50.1/24? (Select one.)
A. Create a 1-to-1 NAT rule for traffic from the 10.0.40.0/24 subnet to addresses on the
10.0.50.0/24 subnet.
B. Add 10.0.40.1/24 as a secondary IP address for the interface.
C. Add IP addresses on the 10.0.40.0/24 subnet to the DHCP Server IP address pool
for this interface.
D. Add a route to 10.0.40.0/24 with the gateway 10.0.50.1. - ANSWER Add 10.0.40.1/24
as a secondary IP address for the interface.
***Which of these options are private IPv4 addresses you can assign to a trusted
interface, as described in RFC 1918, Address Allocation for Private
Internets?(Select three.)
A. 192.168.50.1/24
B. 10.50.1.1/16
C. 198.51.100.1/24
D. 172.16.0.1/16
E. 192.0.2.1/24 - ANSWER 192.168.50.1/24
, 10.50.1.1/16
172.16.0.1/16
The policies in a default Firebox configuration do not allow outgoing traffic from
optional interfaces.
False
True - ANSWER false
When you examine the log messages In Traffic Monitor, you see that some network
packets are denied with an unhandled packet log message. What does this log
massage mean? (Select one.)
A. The packet is denied because the site is on the Blocked Sites List.
B. The packet is denied because it matched a policy.
C. The packet is denied because it matched an IPS signature.
D. The packet is denied because it does not match any firewall policies. - ANSWER The
packet is denied because it does not match any firewall policies.
Which of these actions adds a host to the temporary or permanent blocked sites
list? (Select three.)
A. Enable the AUTO-block sites that attempt to connect option in a deny policy.
B. Add the site to the Blocked Sites Exceptions list.
C. On the Firebox System Manager >Blocked Sites tab, select Add.
D. In Policy Manager, select Setup> Default Threat Protection > Blocked Sites and click
Add. - ANSWER 1. Enable the AUTO-block sites that attempt to connect option in a
deny policy.
(Exam Questions 2021), WatchGuard
Network Security Essentials with 100%
Correct Solutions
***You configured four Device Administrator user accounts for your Firebox. To see
a report of which Device Management users have made changes to the device
configuration, what must you do? (Select two.)
A. Start Firebox System Manager for the device and review the activity for the
Management Users on the Authentication List tab.
B. Connect to Report Manager or Dimension and view the Audit Trail report for
your device.
C. Open WatchGuard Server Center and review the configuration history for
managed devices.
D. Configure your device to send audit trail log messages to your WatchGuard Log
Server or Dimension Log Server. - ANSWER Connect to Report Manager or
Dimension and view the Audit Trail report for your device.
Open WatchGuard Server Center and review the configuration history for
managed devices.
***Which items are included in a Firebox backup image file? (Select four.)
A. Support snapshot
,B. Fireware OS
C. Configuration file
D. Log file
E. Feature keys
F. Certificates
G. Passwords
This question was on the exam but it had different answers.
One of the answer options was policies. I don't believe feature keys was on there.
Also users and roles were on there. - ANSWER Configuration file
Certificates
Passwords
Feature key
***Only 50 clients on the trusted network of your Firebox can connect to the Internet at
the same time. What could cause this? (Select one.)
A. The Live Security feature key is expired.
B. The device feature key allows a maximum of 50 client connections.
C. The DHCP address pool on the trusted interface has only 50 IP addresses.
D. The Outgoing policy allows a maximum of 50 client connections. - ANSWER The DHCP
address pool on the trusted interface has only 50 IP addresses.
Route to 10.0.20.0/24, Gateway 10.0.2.254 - ANSWER Clients on the trusted
network need to connect to a server behind a router on the optional network. Based
on this image, what static route must be added to the Firebox for traffic from clients
on the trusted network to reach a server at 10.0.20.100? (Select one.)
,A. Route to 10.0.20.0/24, Gateway 10.0.2.1
B. Route to 10.0.20.0/24, Gateway 10.0.2.254
C. Route to 10.0.20.0, Gateway 10.0.2.254
D. Route to 10.0.10.0/24, Gateway 10.0.10.1
***The IP address for the trusted interface on your Firebox is 10.0.40.1/24, but you
want to change the IP address for this interface. How can you avoid a network
outage for clients on the trusted network when you change the interface IP address
to 10.0.50.1/24? (Select one.)
A. Create a 1-to-1 NAT rule for traffic from the 10.0.40.0/24 subnet to addresses on the
10.0.50.0/24 subnet.
B. Add 10.0.40.1/24 as a secondary IP address for the interface.
C. Add IP addresses on the 10.0.40.0/24 subnet to the DHCP Server IP address pool
for this interface.
D. Add a route to 10.0.40.0/24 with the gateway 10.0.50.1. - ANSWER Add 10.0.40.1/24
as a secondary IP address for the interface.
***Which of these options are private IPv4 addresses you can assign to a trusted
interface, as described in RFC 1918, Address Allocation for Private
Internets?(Select three.)
A. 192.168.50.1/24
B. 10.50.1.1/16
C. 198.51.100.1/24
D. 172.16.0.1/16
E. 192.0.2.1/24 - ANSWER 192.168.50.1/24
, 10.50.1.1/16
172.16.0.1/16
The policies in a default Firebox configuration do not allow outgoing traffic from
optional interfaces.
False
True - ANSWER false
When you examine the log messages In Traffic Monitor, you see that some network
packets are denied with an unhandled packet log message. What does this log
massage mean? (Select one.)
A. The packet is denied because the site is on the Blocked Sites List.
B. The packet is denied because it matched a policy.
C. The packet is denied because it matched an IPS signature.
D. The packet is denied because it does not match any firewall policies. - ANSWER The
packet is denied because it does not match any firewall policies.
Which of these actions adds a host to the temporary or permanent blocked sites
list? (Select three.)
A. Enable the AUTO-block sites that attempt to connect option in a deny policy.
B. Add the site to the Blocked Sites Exceptions list.
C. On the Firebox System Manager >Blocked Sites tab, select Add.
D. In Policy Manager, select Setup> Default Threat Protection > Blocked Sites and click
Add. - ANSWER 1. Enable the AUTO-block sites that attempt to connect option in a
deny policy.