Updated Dec 18, 2021 Essentials Exam Dumps - PDF Questions and Testing Engine [Q11-Q29]

Share

Updated Dec 18, 2021 Essentials  Exam Dumps - PDF Questions and Testing Engine

New (2021) WatchGuard Essentials  Exam Dumps

NEW QUESTION 11
Only 50 clients on the trusted network of your Firebox can connect to the Internet at the same time. What could cause this? (Select one.)

  • A. The Outgoing policy allows a maximum of 50 client connections.
  • B. The DHCP address pool on the trusted interface has only 50 IP addresses.
  • C. TheLiveSecurity feature key is expired.
  • D. The device feature key allows a maximum of 50 client connections.

Answer: B

 

NEW QUESTION 12
Clients on the trusted network need to connect to a server behind a router on the optional network.

Based on this image, what static route must be added to the Firebox for traffic from clients on the trusted network to reach a server at 10.0.20.100? (Select one.)

  • A. Route to 10.0.20.0/24,Gateway 10.0.2.254
  • B. Route to 10.0.20.0/24,Gateway 10.0.2.1
  • C. Route to 10.0.10.0/24, Gateway 10.0.10.1
  • D. Route to 10.0.20.0, Gateway 10.0.2.254

Answer: D

 

NEW QUESTION 13
With the policies configured as shown in this image, HTTP traffic can be sent and received through branch office VPN tunnel.1 and tunnel.2.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 14
You have a privately addressed email server behind your Firebox. If you want to make sure that all traffic from this server to the Internet appears to come from the public IP address 203.0.113.25, regardless of policies, which from of NAT would you use? (Select one.)

  • A. Create a global dynamic NAT rule for traffic from the email server and set the source IP address to
    203.0.113.25.
  • B. Create a static NAT action for traffic to the email server, and set the source IP address to 203.0.113.25.
  • C. In the SMTP policy that handles traffic from the email server, select the option to apply dynamic NAT to all traffic in the policy and set the source IP address 203.0.113.25.

Answer: A

 

NEW QUESTION 15
When your device is in a default state, to which interface do you connect your management computer so you can use the Quick Setup Wizard or Web Setup Wizard to configure the device? (Select one.)

  • A. Interface 1
  • B. Interface 0
  • C. Console interface
  • D. Any interface

Answer: A

 

NEW QUESTION 16
Which authentication servers can you use with your Firebox? (Select four.)

  • A. RADIUS
  • B. TACACS+
  • C. Active Directory
  • D. Firebox databases
  • E. Kerberos
  • F. Linux Authentication
  • G. LDAP

Answer: A,C,D,G

 

NEW QUESTION 17
While troubleshooting a branch office VPN tunnel, you see this log message:
2014-07-23 12:29:15 iked (203.0.113.10<->203.0.113.20) Peer proposes phase one encryption 3DES, expecting AES What settings could you modify in the local device configuration to resolve this issue? (Select one.)

  • A. BOVPN Tunnel settings
  • B. BOVPN Tunnel Route settings
  • C. BOVPN-Allow policies
  • D. BOVPN Gateway settings

Answer: D

Explanation:
Explanation/Reference:
The WatchGuard BOVPN settings error in this example states phase one encryption. Only the BOVPN Gateway settings can specify phase one settings. BOVPN Tunnel settings specify phase 2 settings.

 

NEW QUESTION 18
After you enable Gateway AntiVirus, IPS, or Application control, how can you make sure the services protect your network from the latest known threats? (Select one.)

  • A. Enable HTTPS deep inspection.
  • B. Configure reputation Enabled Defense.
  • C. Enable automatic signature updates.
  • D. Enable default packet handling.

Answer: C

 

NEW QUESTION 19
Which policies can use the Intrusion Prevention Service to block network attacks? (Select one?)

  • A. Only proxy policies
  • B. Only HTTP and HTTPS Proxy policies
  • C. Only packet filter policies
  • D. Only inbound policies
  • E. All policies

Answer: E

 

NEW QUESTION 20
In the default Firebox configuration file, which policies control management access to the device? (Select two.)

  • A. WatchGuard Web UI
  • B. WatchGuard
  • C. Outgoing
  • D. FTP
  • E. Ping

Answer: A,B

Explanation:
Ping is generated by default as the explanation states but Ping does not manage the device. The policies that manage the device are WatchGuard & WatchGuard Web UI

 

NEW QUESTION 21
Match the monitoring tool to the correct task.
Which is not a Fireware monitoring tool? (Select one)

  • A. FireWatch
  • B. Log Server
  • C. Firebox System Manager - Authentication list
  • D. Traffic Monitor
  • E. Firebox System Manager - Subscription services
  • F. FireBox System Manager - Blocked Sites list

Answer: B

Explanation:
Explanation/Reference:
The Fireware monitor and configuration tools are: Edge Web Manager, Firebox System Manager, HostWatch, and Ping.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181

 

NEW QUESTION 22
Which of these threats can the Firebox prevent with the default packet handling settings? (Select four.)

  • A. Flood attacks
  • B. Denial of service attacks
  • C. Viruses in email messages
  • D. IP spoofing
  • E. Malware in downloaded files
  • F. Access to inappropriate websites
  • G. Port scans

Answer: A,B,D,G

 

NEW QUESTION 23
You can configure the SMTP-proxy policy to restrict email messages and email content based on which of these message characteristics? (Select four.)

  • A. Sender Mail From address
  • B. Maximum email recipients
  • C. Attachment file name and content type
  • D. Check URLs in message with WebBlocker
  • E. Email message size

Answer: A,B,C,E

Explanation:
A: Another way to protect your SMTP server is to restrict incoming traffic to only messages that use your company domain. In this example, we use the mywatchguard.com domain. You can use your own company domain.
1.From the SMTP-Incoming Categories list, select Address > Rcpt To.
2.In the Pattern text box, type*.mywatchguard.com. Click Add.This denies anyemail messages with a Rcpt To address that does not match the company domain.
3.Click OK to close the SMTP Proxy Action Configuration dialog box.
C: In this exercise we will reduce the maximum email size to 5 MB (5, 000 kilobytes).
1.From the SMTP ProxyAction dialog box under the Categories list, select General > General Settings.
2.Find the Limits section. In the Set the maximum email size value box, type 5000.
D: Example: He must configure the Firebox to allow Microsoft Access database files to go through the SMTP proxy. He must also configure the Firebox to deny Apple iTunes MP4 files because of a recent vulnerability announced by Apple.
1.From the SMTP-Incoming Categories list, select Attachments > Content Types.
2.In the Actions to take section,use the None Matched drop-down list to select Allow.
This allows all content types through Firebox to the SMTP server. After Successful Company is able to add in the specific content types they want to allow, they set this parameter to strip content typethat does not match their list of allowed content types.
From the SMTP-Incoming Categories list, select Attachments > Filenames.
4. The filename extension for Microsoft Access databases is ".mdb". In the list of filenames, find and select .mdb. Click Remove. Click Yes to confirm.
3. If no rules match, the Action to take option is set to allow the attachment. In this example, MS Access files are now allowed through the Firebox.
5. In the Pattern text box, type *.mp4. Click Add.
This rule configures the Firebox to deny all files with the Apple iTunes ".mp4" file extension bound for the SMTP server.
E: The Set the maximum email recipient checkbox is used to set the maximum number of email recipients to which a message can be sent in the adjacent text box thatappears, type or select the number of recipients.
The XTM device counts and allows the specified number of addresses through, and then drops the other addresses. For example, if you set the value to 50 and there is a message for 52 addresses, the first 50addresses get the email message. The last two addresses do not get a copy of the message.
Incorrect:
Not B: Webblocker is configured through a HTTP-policy, not through an SMTP policy.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10,pages 125, 126
Reference:http://watchguard.com/help/docs/wsm/xtm_11/en-us/content/enus/proxies/smtp/proxy_smtp_gen_settings_c.html

 

NEW QUESTION 24
The IP address for the trusted interface on your Firebox is 10.0.40.1/24, but you want to change the IP address for this interface. How can you avoid a network outage for clients on the trusted network when you change the interface IP address to 10.0.50.1/24? (Select one.)

  • A. Add IP addresses on the 10.0.40.0/24 subnet to the DHCP Server IP address pool for this interface.
  • B. Add 10.0.40.1/24 as a secondary IP address for the interface.
  • C. Create a 1-to-1 NAT rule for traffic from the 10.0.40.0/24 subnet to addresses on the 10.0.50.0/24 subnet.
  • D. Add a route to 10.0.40.0/24 with the gateway 10.0.50.1.

Answer: B

 

NEW QUESTION 25
Your company denies downloads of executable files from all websites. What can you do to allow users on the network to download executable files from the company's remote website? (Select one.)

  • A. Create a Blocked Sites exception.
  • B. Add an HTTP proxy exception for the company's remote website.
  • C. Create a WebBlocker exception to allow access to the company's remote website.
  • D. Create an IPS exception.
  • E. Configure HTTP Request > URL Paths to allow the company's remote website.

Answer: B

 

NEW QUESTION 26
In the default Firebox configuration file, which policies control management access to the device? (Select two.)

  • A. WatchGuard Web UI
  • B. WatchGuard
  • C. Outgoing
  • D. FTP
  • E. Ping

Answer: A,B

 

NEW QUESTION 27
How can you include log messages from more than one Firebox in a single report generated by Dimension? (Select two.)

  • A. Export report data as a single PDF file for all the devices you want to include in the report.
  • B. Create a report schedule that includes all the devices you want to include in the report.
  • C. You cannot see report data in Dimension for more than one device.
  • D. Create a device group and view the reports for that group.

Answer: B,D

 

NEW QUESTION 28
Which of these options are private IPv4 addresses you can assign to a trusted interface, as described in RFC
1918, Address Allocation for Private Internets? (Select three.)

  • A. 172.16.0.1/16
  • B. 192.0.2.1/24
  • C. 198.51.100.1/24
  • D. 192.168.50.1/24
  • E. 10.50.1.1/16

Answer: A,D,E

Explanation:
Explanation/Reference:

 

NEW QUESTION 29
......


Who should take the Essentials Exam

The Essential Exam certification is an internationally-recognized certification which help to have validation for those professionals who are keen to make their career in configuring and managing Firebox devices that run Fireware.

if a candidate/professional seeks a powerful improvement in career growth needs enhanced knowledge, skills, and talents. The Essential certification provides proof of this advanced knowledge and skill.

 

Updated Verified Pass Essentials Exam - Real Questions & Answers: https://www.examboosts.com/WatchGuard/Essentials-practice-exam-dumps.html

Best Way To Study For WatchGuard Essentials Exam Brilliant Essentials Exam Questions PDF: https://drive.google.com/open?id=1ek0Pd5pqxjuW-V_32ymPtbR_KSkG3Bik