[Nov-2021] Essentials Pre-Exam Practice Tests | Exam Questions and Answers for Fireware Essentials Study Guide
Fireware Essentials Exam Certification Sample Questions
Essential Exam Certified Professional salary
The average salary of a Essential Exam Certified Expert in
- India. - 8,00,327 INR
- United State - 80,200 USD
- Europe - 40,500 EURO
- England - 50,000 POUND
Understanding functional and technical aspects of Essentials Network and Network Security Basics
The following will be discussed here:
- IPv4 addresses, subnetting, and routing
- Understand basic networking concepts that are not unique to the Firebox.
- MAC addresses
- Network Address Translation
- Packet headers (TCP, IP, HTTP)
- Network services, ports, and protocols
- Network and Network Security Basics
NEW QUESTION 32
With the policies configured as shown in this image, HTTP traffic can be sent and received through branch office VPN tunnel.1 and tunnel.2.
- A. True
- B. False
Answer: A
NEW QUESTION 33
Which WatchGuard tools can you use to review the log messages generated by your Firebox? (Select three).
- A. Firebox System Manager > Status Report
- B. Fireware XTM Web UI > Traffic Monitor
- C. WatchGuard System Manager > Policy Manager
- D. Dimension > Log manager
- E. Firebox SystemManager > Traffic Monitor
Answer: B,D,E
Explanation:
A: You can use Firebox System Manager (FSM) to see log messages from your XTM device as they occur.
Reference:http://www.watchguard.com/help/docs/wsm/xtm_11/en-US/index.html#cshid=en-US/fsm/log_msgs_traffic_mon_wsm.html
D: You can use Firebox System Manager to see log messages in real-time on the Traffic Monitor tab. You can also examine log messages with Log Manager or WatchGuard Dimension.
B: After you connect to WatchGuard WebCenter, you can review the log messages sent from your XTM devices to your WatchGuard Log Server. Log Manager enables you to see log messages from your device for any period of time you specify, if log messages were generated in the selected time frame. To see log messages for an XTM device as they are generated, in real-time, you can use Firebox System Manager Traffic Monitor.
Reference:http://www.watchguard.com/help/docs/wsm/XTM_11/en-US/index.html#en-US/logging/log_mgr_view_device_wsm.html
Incorrect:
Not C: The Status Report tab shows statistics about Firebox orXTM device traffic and performance. It does not display log messages.
To see the Status Report:
Start Firebox System Manager.
Select the Status Report tab.
Screen shot of the Firebox System Manager Status Report
NEW QUESTION 34
Match each WatchGuard Subscription Service with its function.
Cloud based service that controls access to website based on a site's previous behavior. (Choose one).
- A. WebBlocker
- B. Intrusion Prevention Server IPS
- C. Application Control
- D. Quarantine Server
- E. Reputation Enable Defense RED
- F. Data Loss Prevention DLP
Answer: E
Explanation:
Explanation/Reference:
Reputation Enable Device (RED) is a cloud-based reputation service that controls user's ability to get main access to web malicious sites. Works in concert with the WebBlocker module.
Reference: http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html
NEW QUESTION 35
If your Firebox has a single public IP address, and you want to forward inbound traffic to internal hosts based on the destination port, which type of NAT should you use? (Select one.)
- A. Dynamic NAT
- B. 1-to-1 NAT
- C. Static NAT
Answer: C
NEW QUESTION 36
After you enable spamBlocker, your users experience no reduction in the amount of spam they receive. What could explain this? (Select three.)
- A. The Maximum File Size to Scan option is set too high.
- B. spamBlocker Virus Outbreak Detection is not enabled.
- C. Connections cannot be resolved to the spamBlocker servers because DNS is not configured on the Firebox.
- D. The spamBlocker action for Confirmed Spam is set to Allow.
- E. A spamBlocker exception is configured to allow traffic from sender *.
Answer: C,D,E
Explanation:
Explanation/Reference:
A: Spamblocker requires DNS to be configured on your XTM device
B: If you use spamBlocker with the POP3 proxy, you have only two actions to choose from: Add Subject Tag and Allow. Allow lets spam email messages go through the Firebox without a tag.
D: The Firebox might sometimes identify a message as spam when it is not spam. If you know the address of the sender, you can configure the Firebox with an exception that tells it not to examine messages from that source address or domain.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 138
NEW QUESTION 37
Clients on the trusted network need to connect to a server behind a router on the optional network. Based on this image, what static route must be added to the Firebox for traffic from clients on the trusted network to reach a server at 10.0.20.100? (Select one.)
- A. Route to 10.0.20.0/24, Gateway 10.0.2.1
- B. Route to 10.0.10.0/24, Gateway 10.0.10.1
- C. Route to 10.0.20.0/24, Gateway 10.0.2.254
- D. Route to 10.0.20.0, Gateway 10.0.2.254
Answer: C
Explanation:
Explanation/Reference:
We must add a trusted static route to the 10.0.20.0/24 network through the 10.0.2.254 gateway.
NEW QUESTION 38
Match the monitoring tool to the correct task.
Which is not a Fireware monitoring tool? (Select one)
- A. FireWatch
- B. Log Server
- C. Firebox System Manager - Authentication list
- D. Traffic Monitor
- E. Firebox System Manager - Subscription services
- F. FireBox System Manager - Blocked Sites list
Answer: B
Explanation:
The Fireware monitor and configuration tools are: Edge Web Manager, Firebox System Manager, HostWatch, and Ping.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59,
NEW QUESTION 39
In the network configuration in this image, which aliases is Eth2 a member of? (Select three.)
- A. Any-Trusted
- B. Any
- C. Optional-1
- D. Any-optional
- E. Any-External
Answer: B,C,D
NEW QUESTION 40
You can use Firebox System Manager to download a PCAP file that includes packet information about the protocols that manage traffic on your network.
- A. True
- B. False
Answer: A
NEW QUESTION 41
Your company denies downloads of executable files from all websites. What can you do to allow users on the network to download executable files from the company's remote website? (Select one.)
- A. Create a Blocked Sites exception.
- B. Add an HTTP proxy exception for the company's remote website.
- C. Create a WebBlocker exception to allow access to the company's remote website.
- D. Create an IPS exception.
- E. Configure HTTP Request > URL Paths to allow the company's remote website.
Answer: B
NEW QUESTION 42
Match the monitoring tool to the correct task.
Which tool can view a list of users connected to the Firebox? (Select one)
- A. FireWatch
- B. Log Server
- C. Traffic Monitor
- D. Firebox System Manager - Subscription services
- E. FireBox System Manager - Blocked Sites list
- F. Firebox System Manager - Authentication list
Answer: F
Explanation:
You can viewa list of users connected to the Firebox through HostWatch, and you can also use Authentication List, which identifiesthe IP addresses and user names of all the users that are authenticated to the Firebox.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181
NEW QUESTION 43
Which takes precedence: WebBlocker category match or a WebBlocker exception?
- A. WebBlocker category match
- B. WebBlocker exception
Answer: B
NEW QUESTION 44
How can you include log messages from more than one Firebox in a single report generated by Dimension? (Select two.)
- A. Export report data as a single PDF file for all the devices you want to include in the report.
- B. Create a report schedule that includes all the devices you want to include in the report.
- C. You cannot see report data in Dimension for more than one device.
- D. Create a device group and view the reports for that group.
Answer: B,D
NEW QUESTION 45
Users on the trusted network cannot browse Internet websites. Based on the configuration shown in this image, what could be the problem with this policy configuration? (Select one.)
- A. The default Outgoing policy has been removed and there is no policy to allow DNS traffic.
- B. The HTTP-proxy allows Any-Trusted and Any-Optional to Any-External.
- C. The HTTP-proxy policy is configured for the wrong port.
- D. The HTTP-proxy policy has higher precedence than the HTTPS-proxy policy.
Answer: A
NEW QUESTION 46
Clients on the trusted network need to connect to a server behind a router on the optional network. Based on this image, what static route must be added to the Firebox for traffic from clients on the trusted network to reach a server at 10.0.20.100? (Select one.)
- A. Route to 10.0.20.0/24, Gateway 10.0.2.1
- B. Route to 10.0.10.0/24, Gateway 10.0.10.1
- C. Route to 10.0.20.0/24, Gateway 10.0.2.254
- D. Route to 10.0.20.0, Gateway 10.0.2.254
Answer: C
Explanation:
We must add a trusted static route to the 10.0.20.0/24 network through the 10.0.2.254 gateway.
NEW QUESTION 47
You can configure your Firebox to send log messages to how many WatchGuard Log Servers at the same time? (Select one.)
- A. One
- B. Two
- C. As many as you have configured on your network.
Answer: C
NEW QUESTION 48
You have a privately addressed email server behind your Firebox. If you want to make sure that all traffic from this server to the Internet appears to come from the public IP address 203.0.113.25, regardless of policies, which from of NAT would you use? (Select one.)
- A. In the SMTP policy that handles traffic from the email server, select the option to apply dynamic NAT to all traffic in the policy and set the source IP address 203.0.113.25.
- B. Create a static NAT action for traffic to the email server, and set the source IP address to
203.0.113.25. - C. Create a global dynamic NAT rule for traffic from the email server and set the source IP address to 203.0.113.25.
Answer: C
NEW QUESTION 49
An email newsletter about sales from an external company is sometimes blocked by spamBlocker. What option could you choose to make sure the newsletter is delivered to your users? (Select one.)
- A. Set the spamBlocker action to quarantine the email for later retrieval.
- B. Add a spamBlocker exception based on the From field of the newsletter email.
- C. Set the spamBlocker virus outbreak detection action to allow emails from the newsletter source.
- D. Add a spamBlocker subject tag for bulk email messages.
Answer: D
NEW QUESTION 50
While troubleshooting a branch office VPN tunnel, you see this log message:
2014-07-23 12:29:15 iked (203.0.113.10<->203.0.113.20) Peer proposes phase one encryption 3DES, expecting AES
What settings could you modify in the local device configuration to resolve this issue? (Select one.)
- A. BOVPN Tunnel settings
- B. BOVPN Tunnel Route settings
- C. BOVPN-Allow policies
- D. BOVPN Gateway settings
Answer: D
Explanation:
The WatchGuard BOVPN settings error in this example states phase one encryption. Only the BOVPN Gateway settings can specify phase one settings. BOVPN Tunnel settings specify phase 2 settings.
NEW QUESTION 51
You can configure your Firebox to automatically redirect users to the Authentication Portal page.
- A. True
- B. False
Answer: A
NEW QUESTION 52
You need to create an HTTP-proxy policy to a specific domain for software updates (example.com). The update site has multiple subdomains and dynamic IP addresses on a content delivery network. Which of these options is the best way to define the destination in your HTTP-proxy policy? (Select one.)
- A. Configure an FQDN for *.example.com.
- B. Create an alias for all subdomains and known IP addresses for example.com.
- C. Add IP addresses that correspond to each software update server in the domain.
- D. Configure a host name for update.example.com.
Answer: C
NEW QUESTION 53
If your Firebox has a single public IP address, and you want to forward inbound traffic to internal hosts based on the destination port, which type of NAT should you use? (Select one.)
- A. Dynamic NAT
- B. 1-to-1 NAT
- C. Static NAT
Answer: C
Explanation:
https://www.watchguard.com/training/fireware/10/fireware10_basics.pdf
See page 76: Static NAT allows inbound connections on specific ports to one or more public servers from a single external IP address. The Firebox changes the destination IP address of the packets and forwards them based on the original destination port number.
NEW QUESTION 54
Clients on the trusted network need to connect to a server behind a router on the optional network. Based on this image, what static route must be added to the Firebox for traffic from clients on the trusted network to reach a server at 10.0.20.100? (Select one.)
- A. Route to 10.0.20.0/24, Gateway 10.0.2.1
- B. Route to 10.0.10.0/24, Gateway 10.0.10.1
- C. Route to 10.0.20.0/24, Gateway 10.0.2.254
- D. Route to 10.0.20.0, Gateway 10.0.2.254
Answer: C
Explanation:
Explanation/Reference:
We must add a trusted static route to the 10.0.20.0/24 network through the 10.0.2.254 gateway.
NEW QUESTION 55
Which of these options are private IPv4 addresses you can assign to a trusted interface, as described in RFC 1918, Address Allocation for Private Internets? (Select three.)
- A. 172.16.0.1/16
- B. 192.0.2.1/24
- C. 198.51.100.1/24
- D. 192.168.50.1/24
- E. 10.50.1.1/16
Answer: A,D,E
NEW QUESTION 56
Match each WatchGuard Subscription Service with its function.
Uses full-system emulation analysis to identify characteristics and behavior of zero-day malware. (Choose one).
- A. Spam Blocker
- B. Gateway / Antivirus
- C. WebBlocker
- D. Reputation Enable Defense RED
- E. Intrusion Prevention Server IPS
- F. DataLoss Prevention DLP
- G. APT Blocker
- H. Application Control
- I. Quarantine Server
Answer: G
Explanation:
APT Blocker is intended to stop malware and zero-day threats that are trying to invade anorganization's network.
APT Blocker uses a next-gen sandbox to get detailed views into the execution of a malware program. After first running through other security services, files are fingerprinted and checked against an existing database - first on theappliance and then in the cloud. If the file has never been seen before, it is analyzed using the system emulator, which monitors the execution of all instructions. It can spot the evasion techniques that other sandboxes miss.
Reference:http://www.watchguard.com/wgrd-products/security-modules/apt-blocker
NEW QUESTION 57
......
How to study the Essentials Exam
Preparation of certification exams can be done from two different resource types. One of them is study guides, reference books and study forums that are elaborated and appropriate for building information from ground up. second option is video tutorials and lectures to ease the pain of through study and are relatively make the study process more interesting nevertheless it need concentration and dedicated time from the learner. Candidates who wish to create a solid foundation altogether examination topics and connected technologies typically mix video lectures with study guides to take maximum advantages of each but practicing exams through our provided exam engines could be one of best tool which is generally ignored by most candidates. Practice exams are designed with our experts to make exam prospects test their knowledge on skills attained in course which help candidates to become comfortable and familiar with the real exam environment. Statistics have indicated exam anxiety plays much bigger role of students failure in exam than the fear of the unknown. TrainingDump expert team recommends preparing some notes on these topics along with it don’t forget to practice WatchGaurd Essentials Dumps which had been written by our WatchGaurd certified experts, each of these can assist you loads to clear this exam with excellent marks.
WatchGuard Exam Practice Test To Gain Brilliante Result: https://www.trainingdump.com/WatchGuard/Essentials-practice-exam-dumps.html
Tested Material Used To Essentials: https://drive.google.com/open?id=1sykswEJnezGxHkcmaeHgO-VwNVNmLeJe