Skip to content

Essentials Practice Questions

Prepare for Essentials with more than an answer.

75 questions in the full set12 sample questionsUpdated Sep 16, 2021
  1. 1

    If your Firebox has a single public IP address, and you want to forward inbound traffic to internal hosts based on the destination port, which type of NAT should you use? (Select one.)

    Show answer details

    Correct answer: A

    A

  2. 2

    Which of these options must you configure in an HTTPS-proxy policy to detect credit card numbers in HTTP traffic that is encrypted with SSL? (Select two.)

    Show answer details

    Correct answer: D, E

    D, E

    D, E

  3. 3

    What is one reason that users could see a certificate warning in their web browsers when they connect to Fireware XTM Web UI? (Select one.)

    Show answer details

    Correct answer: A

    A

  4. 4

    Which tool can add an IP address for the Firebox to permanently block?

    Show answer details

    Correct answer: A

    Explanation:
    Block a site permanently The Successful Company network administrator has been driven to distraction recently by a script kiddy using addresses in the 192.136.15.0/24 network to run probes of the Successful network. In this exercise, we permanently block all connections from that network. 1. From Policy Manager, select Setup > Default Threat Protection > Blocked Sites.
    The Stocked Sites Configuration dialog box opens. 2. Onttie Blocked Sites tab, click Add. 3. The Add Site dialog box opens. 3. Use the Choose Type drop-down list to select Network IP. In the Value text box, type 192.136.15.0/ 24. 4. Click OK.
    The entry appears in the Blocked Sites list. With this configuration, the Firebox blocks all packets to and from the 192.136.15.0/24 network range.
    Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181

  5. 5

    After you enable Gateway AntiVirus, IPS, or Application control, how can you make sure the services protect your network from the latest known threats? (Select one.)

    Show answer details

    Correct answer: C

    C

  6. 6

    Match each type of NAT with the correct description: Conserves IP addresses and hides the internal topology of your network. (Choose one)

    Show answer details

    Correct answer: B

    Explanation:
    Dynamic NAT is also known as IP masquerading. With dynamic NAT many computers can connect to the Internet from one public IP address. Dynamic NAT gives more security for internal hosts that use
    Reference: http://www.watchguard.com/help/docs/wsm/xtm 11/en-US/index.html#en-US/nat/nat dynamic use c.html%3FTocPath%3DNetwork%2520Address%2520Translation%2520(NAT)%7CAbout(?

Create an account to continue.