Free Fortinet FortiDDoS Exam Braindumps (page: 2)

Which is true regarding packets that match a do-not-track policy with the action Track and Allow?

  1. Packets are never dropped.
  2. Source IP addresses are added to the legitimate IP (LIP) table.
  3. Packets are not included in the statistics for threshold estimation.
  4. Packets are assigned to SPP 0.

Answer(s): A



Regarding the switching SPP feature, what is used to determine when FortiDDoS switches the traffic to an alternate SPP?

  1. Traffic volume
  2. Destination IP addresses
  3. Mitigated attacks
  4. Blocked packets

Answer(s): A



A FortiDDoS device is connected between a protected server and an Internet router. For the aggressive aging feature, the administrator must manually add the router internal interface MAC address to the FortiDDoS configuration.
Why does the FortiDDoS need this information?

  1. To send RST packets to the protected server spoofing the router internal interface MAC address.
  2. To allow incoming traffic only from that specific MAC address.
  3. To determine which traffic direction is incoming and which traffic direction is outgoing.
  4. To allow outgoing traffic only to that specific MAC address.

Answer(s): A



As the exhibit shows, a FortiDDoS port2 is connected to the protected server. Its port1 is connected to the Internet. The FortiDDoS has 8 interfaces for user traffic. The exhibit also shows a screenshot of the unit dashboard.





The administrator noticed that the statistics are showing all the traffic coming from the Internet to the protected server as outbound, instead of inbound. Based on the exhibit, what is the cause of this mislabeling?

  1. The protected server is connected to a wrong FortiDDoS interface. It must be connected to an interface from port 5 to port 8.
  2. SPP 0 is operating in detection mode.
  3. The SPP 0 link is down.
  4. FortiDDoS interfaces are wrongly connected. The interface port1 must be connected to the protected server and port2 must be connected to the Internet.

Answer(s): D






Post your Comments and Discuss Fortinet FortiDDoS exam prep with other Community members:

FortiDDoS Exam Discussions & Posts