
New Essentials Test Materials & Valid Essentials Test Engine
Essentials Updated Exam Dumps [2022] Practice Valid Exam Dumps Question
Essential Exam Certified Professional salary
The average salary of a Essential Exam Certified Expert in
- Europe - 40,500 EURO
- United State - 80,200 USD
- India. - 8,00,327 INR
- England - 50,000 POUND
NEW QUESTION 13
If you use an external authentication server for mobile VPN, which option must you complete before remote users can authenticate? (Select one.)
- A. Add the Mobile VPN user group and remote users to your authentication server.
- B. Reboot the authentication server.
- C. Add the remote users to a Mobile VPN user group on your Firebox.
- D. Create aliases for each remote user's virtual IP address.
Answer: A
Explanation:
http://www.watchguard.com/help/docs/wsm/xtm_11/en-us/content/en-us/mvpn/ipsec/mvpn_ipsec_ext_auth_server_config_wsm.html
NEW QUESTION 14
Match each WatchGuard Subscription Service with its function.
Controls access to website based on content categories. . (Choose one).
- A. Gateway / Antivirus
- B. Reputation Enable Defense RED
- C. Intrusion Prevention Server IPS
- D. Application Control
- E. WebBlocker
Answer: E
Explanation:
WebBlocker controls access to the good and bad places that are reachable on the web,preventing users from gaining access to sites that have evil intentions.
If you configure WebBlocker to use the Websense cloud for WebBlocker lookups, WebBlocker uses the Websense content categories. A web site is added to a category when the content of the web site meets the criteria for the content category.
Reference:http://www.tomsitpro.com/articles/network-security-solutions-guide,2-866-6.html
NEW QUESTION 15
Which WatchGuard Subscription Service must be enabled in a proxy policy before you can use APT Blocker?
(Select one.)
- A. WebBlocker
- B. IPS
- C. Gateway Antivirus
- D. RED
- E. Application Control
Answer: C
NEW QUESTION 16
Match each WatchGuard Subscription Service with its function.
Cloud based service that controls access to website based on a site's previous behavior. (Choose one).
- A. WebBlocker
- B. Reputation Enable Defense RED
- C. QuarantineServer
- D. Intrusion Prevention Server IPS
- E. Data Loss Prevention DLP
- F. Application Control
Answer: B
Explanation:
Reputation Enable Device (RED) is a cloud-based reputation service that controls user's ability to get main access to web malicious sites. Works in concert with the WebBlocker module.
Reference:http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html
NEW QUESTION 17
If you use an external authentication server for mobile VPN, which option must you complete before remote users can authenticate? (Select one.)
- A. Add the Mobile VPN user group and remote users to your authentication server.
- B. Reboot the authentication server.
- C. Add the remote users to a Mobile VPN user group on your Firebox.
- D. Create aliases for each remote user's virtual IP address.
Answer: A
NEW QUESTION 18
A user receives a deny message that the installation file (install.exe) is blocked by the HTTP-proxy policy and cannot be downloaded. Which HTTP proxy action rule must you modify to allow download of the installation file? (Select one.)
- A. HTTP Response > Header Fields
- B. HTTP Request > Request Methods
- C. HTTP Request > Authorization
- D. WebBlocker
- E. HTTP Response > Body Content Types
Answer: C
NEW QUESTION 19
Match the monitoring tool to the correct task.
Which is not a Fireware monitoring tool? (Select one)
- A. Traffic Monitor
- B. Firebox System Manager - Subscription services
- C. FireWatch
- D. FireBox System Manager - Blocked Sites list
- E. Log Server
- F. Firebox System Manager - Authentication list
Answer: E
Explanation:
The Fireware monitor and configuration tools are: Edge Web Manager, Firebox System Manager, HostWatch, and Ping.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59,
NEW QUESTION 20
What is the best method to downgrade the version of Fireware OS on your Firebox without losing all device configuration settings? (Select one.)
- A. Use the downgrade feature on Policy Manager to select a previous of Fireware OS.
- B. Change the OS compatibility setting in Policy Manager to downgrade the device. Then use Policy Manager to save the configuration to the device.
- C. Restore a saved backup image that was created for the device before the last Fireware OS upgrade.
- D. Use the Upgrade OS feature in Fireware Web UI to install the sysa_dl file for an order version of Fireware OS.
Answer: C
NEW QUESTION 21
In a Mobile VPN configuration, why would you choose default route VPN over split tunnel VPN? (Select one.)
- A. Default route VPN allows your Firebox to examine all remote user traffic
- B. Default route VPN uses less bandwidth
- C. Default route VPN automatically allows dynamic NAT
- D. Default route VPN uses less processing power
Answer: C
NEW QUESTION 22
Match the monitoring tool to the correct task.
Which is not a Fireware monitoring tool? (Select one)
- A. Traffic Monitor
- B. Firebox System Manager - Subscription services
- C. FireWatch
- D. FireBox System Manager - Blocked Sites list
- E. Log Server
- F. Firebox System Manager - Authentication list
Answer: E
Explanation:
Explanation/Reference:
The Fireware monitor and configuration tools are: Edge Web Manager, Firebox System Manager, HostWatch, and Ping.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181
NEW QUESTION 23
If you disable the Outgoing policy, which policies must you add to allow trusted users to connect to commonly used websites? (Select three.)
- A. NAT policy
- B. DNS port 53
- C. FTP port 21
- D. HTTPS port 443
- E. HTTP port 80
Answer: B,D,E
Explanation:
TCP-UDP packet filter
If you decide to remove the Outgoing policy, you must add a policy for any type of traffic you want to allow through the Firebox. If you remove the Outgoing policy and then decide you want to allow all TCPand UDP connections through the Firebox again, you must add the TCP-UDP packet filter to provide the same function. This is because the Outgoing policy does not appear in the list of standard policies available from Policy Manager.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 97
NEW QUESTION 24
In a Mobile VPN configuration, why would you choose default route VPN over split tunnel VPN? (Select one.)
- A. Default route VPN allows your Firebox to examine all remote user traffic
- B. Default route VPN uses less bandwidth
- C. Default route VPN automatically allows dynamic NAT
- D. Default route VPN uses less processing power
Answer: C
NEW QUESTION 25
How is a proxy policy different from a packet filter policy? (Select two.)
- A. Only a proxy policy uses the IP source,destination, and port to control network traffic.
- B. Only a proxy policy can prevent specific threats without blocking the entire connection.
- C. Only a proxy works at the application, network, and transport layers to examine all connection data.
- D. Only a proxy policy examines information in the IP header.
Answer: B,C
Explanation:
C: Proxies can prevent potential threats from reaching your network without blocking the entire connection.
D: A proxy operates at the application layer, as well as the network and transport layers of a TCP/IP packet, while a packet filter operates onlyat the network and transport protocol layers.
Incorrect:
Not A: A packet filter examines each packet's IP header to control the network traffic into and out of your network.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 95
NEW QUESTION 26
You need to create an HTTP-proxy policy to a specific domain for software updates (example.com). The update site has multiple subdomains and dynamic IP addresses on a content delivery network. Which of these options is the best way to define the destination in your HTTP-proxy policy? (Select one.)
- A. Configure a host name for update.example.com.
- B. Create an alias for all subdomains and known IP addresses for example.com.
- C. Configure an FQDN for *.example.com.
- D. Add IP addresses that correspond to each software update server in the domain.
Answer: D
NEW QUESTION 27
Which tool is used to see a treemap visualization of the traffic through your Firebox? (Select one)
- A. Log Server
- B. Traffic Monitor
- C. Firebox System Manager - Subscription services
- D. FireBox System Manager - Blocked Sites list
- E. FireWatch
- F. Firebox System Manager - Authentication list
Answer: E
Explanation:
Explanation/Reference:
The FireWatch page is separated into tabs of data that is presented in a Treemap Visualization. The treemap is a widget that proportionally sizes blocks in the display to represent the data for that tab. The largest blocks on the tab represent the largest data users. The data is sorted by the tab you select and the type you select from the drop-down list at the top right of the page.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181
NEW QUESTION 28
Your company denies downloads of executable files from all websites. What can you do to allow users on the network to download executable files from the company's remote website? (Select one.)
- A. Create a WebBlocker exception to allow access to the company's remote website.
- B. Create a Blocked Sites exception.
- C. Add an HTTP proxy exception for the company's remote website.
- D. Create an IPS exception.
- E. Configure HTTP Request > URL Paths to allow the company's remote website.
Answer: C
NEW QUESTION 29
If you disable the Outgoing policy, which policies must you add to allow trusted users to connect to commonly used websites? (Select three.)
- A. NAT policy
- B. DNS port 53
- C. FTP port 21
- D. HTTPS port 443
- E. HTTP port 80
Answer: B,D,E
Explanation:
Explanation/Reference:
TCP-UDP packet filter
If you decide to remove the Outgoing policy, you must add a policy for any type of traffic you want to allow through the Firebox. If you remove the Outgoing policy and then decide you want to allow all TCP and UDP connections through the Firebox again, you must add the TCP-UDP packet filter to provide the same function. This is because the Outgoing policy does not appear in the list of standard policies available from Policy Manager.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 97
NEW QUESTION 30
Which of these actions adds a host to the temporary or permanent blocked sites list? (Select three.)
- A. In Policy Manager, select Setup> Default Threat Protection > Blocked Sites and click Add.
- B. On the Firebox System Manager >Blocked Sites tab, select Add.
- C. Add the site to the Blocked Sites Exceptions list.
- D. Enable the AUTO-block sites that attempt to connect option in a deny policy.
Answer: A,B,D
NEW QUESTION 31
......
Understanding functional and technical aspects of Essentials Authentication and VPNs
The following will be discussed here:
- Mobile VPN routing options and protocols
- Authentication servers
- Understand user authentication and VPN settings on the Firebox
- Users and groups in policies
- Firebox authentication portal
- Branch Office VPN gateways and tunnel routes
- Branch Office VPN and NAT
- BOVPN virtual interfaces
Essentials Sample with Accurate & Updated Questions: https://www.pass4sures.top/Fireware-Essentials/Essentials-testking-braindumps.html
Essentials Exam Info and Free Practice Test | Pass4sures: https://drive.google.com/open?id=1Q3OBdk1b-JE7tLTN4Dj29mpCrEqCVQvN