有効なSAP Certified Application Associate C-HRHFC-2311問題集はあなたの合格を必ず保証します [Q56-Q75]

Share

有効なSAP Certified Application Associate C-HRHFC-2311問題集はあなたの合格を必ず保証します

C-HRHFC-2311問題集でリアル試験問題でテストエンジン問題集でトレーニング

質問 # 56
Which three security features require the intrusion prevention system (IPS) engine to function? (Choose three.)

  • A. Antivirus in flow-based inspection
  • B. Application control
  • C. DNS filter
  • D. Web filter in flow-based inspection
  • E. Web application firewall

正解:A、B、D

解説:
https://docs.fortinet.com/document/fortigate/7.0.0/new-features/739623/dns-filter-handled-by-ips-engine-in-flow-mode


質問 # 57
Which two protocol options are available on the CLI but not on the GUI when configuring an SD-WAN Performance SLA? (Choose two.)

  • A. ping
  • B. TWAMP
  • C. udp-echo
  • D. DNS

正解:B、C


質問 # 58
An administrator does not want to report the logon events of service accounts to FortiGate. What setting on the collector agent is required to achieve this?

  • A. Add user accounts to the FortiGate group fitter.
  • B. Add the support of NTLM authentication.
  • C. Add user accounts to Active Directory (AD).
  • D. Add user accounts to the Ignore User List.

正解:D


質問 # 59
An administrator wants to configure Dead Peer Detection (DPD) on IPSEC VPN for detecting dead tunnels. The requirement is that FortiGate sends DPD probes only when no traffic is observed in the tunnel.
Which DPD mode on FortiGate will meet the above requirement?

  • A. On Idle
  • B. Enabled
  • C. Disabled
  • D. On Demand

正解:A


質問 # 60
An administrator needs to configure VPN user access for multiple sites using the same soft FortiToken. Each site has a FortiGate VPN gateway. What must an administrator do to achieve this objective?

  • A. The administrator must use the user self-registration server.
  • B. The administrator can use a third-party radius OTP server.
  • C. The administrator must use a FortiAuthenticator device
  • D. The administrator can register the same FortiToken on more than one FortiGate.

正解:C

解説:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-FortiToken-for-multiple-units/ta-p/194435


質問 # 61
A team manager has decided that, while some members of the team need access to a particular website, the majority of the team does not Which configuration option is the most effective way to support this request?

  • A. Implement a web filter category override for the specified website
  • B. Implement web filter quotas for the specified website
  • C. Implement a DNS filter for the specified website.
  • D. Implement web filter authentication for the specified website.

正解:D


質問 # 62
What are two characteristics of FortiGate HA cluster virtual IP addresses? (Choose two.)

  • A. A change in the virtual IP address happens when a FortiGate device joins or leaves the cluster.
  • B. Virtual IP addresses are used to distinguish between cluster members.
  • C. The primary device in the cluster is always assigned IP address 169.254.0.1.
  • D. Heartbeat interfaces have virtual IP addresses that are manually assigned.

正解:A、B

解説:
Fortigate Infrastructure 7.2 Study Guide page 301
FortiGate Infrastructure 7.2 Study Guide (p.301):
"FGCP automatically assigns the heartbeat IP addresses based on the serial number of each device. The IP address 169.254.0.1 is assigned to the device with the highest serial number."
"A change in the heartbeat IP addresses may happen when a FortiGate device joins or leaves the cluster."
"The HA cluster uses the heartbeat IP addresses to distinguish the cluster members and synchronize data."
https://networkinterview.com/fortigate-ha-high-availability/


質問 # 63
What are two scanning techniques supported by FortiGate? (Choose two.)

  • A. Trojan scan
  • B. Machine learning scan
  • C. Ransomware scan
  • D. Antivirus scan

正解:B、D

解説:
FortiGate Security 7.2 Study Guide (p.341):
"Like viruses, which use many methods to avoid detection, FortiGate uses many techniques to detect viruses. These detection techniques include:
* Antivirus scan
* Grayware scan
* Machine learning (AI) scan
If all antivirus features are enabled, FortiGate applies the following scanning order: antivirus scan, followed by grayware scan, followed by AI scan."


質問 # 64
Which two statements are correct about SLA targets? (Choose two.)

  • A. SLA targets are optional.
  • B. SLA targets are required for SD-WAN rules with a Best Quality strategy.
  • C. SLA targets are used only when referenced by an SD-WAN rule.
  • D. You can configure only two SLA targets per one Performance SLA.

正解:A、C


質問 # 65
An administrator wants to simplify remote access without asking users to provide user credentials.
Which access control method provides this solution?

  • A. ZTNA IP/MAC filtering mode
  • B. SSL VPN
  • C. L2TP
  • D. ZTNA access proxy

正解:D

解説:
FortiGate Infrastructure 7.2 Study Guide (p.165): "ZTNA access proxy allows users to securely access resources through an SSL-encrypted access proxy. This simplifies remote access by eliminating the use of VPNs." This is true because ZTNA access proxy is a feature that allows remote users to access internal applications without requiring VPN or user credentials. ZTNA access proxy uses a secure tunnel between the user's device and the FortiGate, and authenticates the user based on device identity and context. The user only needs to install a lightweight agent on their device, and the FortiGate will automatically assign them to the appropriate application group based on their device profile. This simplifies remote access and enhances security by reducing the attack surface12


質問 # 66
Refer to the exhibit, which contains a static route configuration.
An administrator created a static route for Amazon Web Services.

Which CLI command must the administrator use to view the route?

  • A. diagnose firewall proute list
  • B. get router info routing-table database
  • C. get internet-service route list
  • D. get router info routing-table all

正解:A

解説:
ISDB static route will not create entry directly in routing-table. Reference: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Creating-a-static-route-for-Predefined-Internet/ta-p/198756 and here https://community.fortinet.com/t5/FortiGate/Technical-Tip-Verify-the-matching-policy-route/ta-p/190640 FortiGate Infrastructure 7.2 Study Guide (p.16 and p.59): "Even though they are configured as static routes, ISDB routes are actually policy routes and take precedence over any other routes in the routing table. As such, ISDB routes are added to the policy routing table." "FortiOS maintains a policy route table that you can view by running the diagnose firewall proute list command."


質問 # 67
Which two statements are correct about NGFW Policy-based mode? (Choose two.)

  • A. NGFW policy-based mode policies support only flow inspection
  • B. NGFW policy-based mode can only be applied globally and not on individual VDOMs
  • C. NGFW policy-based mode supports creating applications and web filtering categories directly in a firewall policy
  • D. NGFW policy-based mode does not require the use of central source NAT policy

正解:A、C


質問 # 68
Which three pieces of information does FortiGate use to identify the hostname of the SSL server when SSL certificate inspection is enabled? (Choose three.)

  • A. The serial number in the server certificate
  • B. The host field in the HTTP header
  • C. The server name indication (SNI) extension in the client hello message
  • D. The subject alternative name (SAN) field in the server certificate
  • E. The subject field in the server certificate

正解:C、D、E

解説:
A) The server name indication (SNI) extension in the client hello message. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The SNI extension is a feature of the TLS protocol that allows a client to indicate the hostname of the server it wants to connect to during the TLS handshake. This helps the server to present the appropriate certificate for the requested hostname, especially when the server hosts multiple domains on the same IP address1. FortiGate can use the SNI extension in the client hello message to identify the hostname of the SSL server and verify it against the server certificate2.
B) The subject alternative name (SAN) field in the server certificate. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The SAN field is an extension of the X.509 certificate standard that allows a certificate to specify multiple hostnames or IP addresses that are valid for the certificate. This helps the certificate to support multiple domains or subdomains on the same server, or multiple servers with different IP addresses3. FortiGate can use the SAN field in the server certificate to identify the hostname of the SSL server and verify it against the client request2.
E) The subject field in the server certificate. This is correct. This is a piece of information that FortiGate uses to identify the hostname of the SSL server when SSL certificate inspection is enabled. The subject field is a part of the X.509 certificate standard that contains information about the identity of the entity that owns the certificate, such as common name, organization, country, and so on. The common name usually specifies the hostname or domain name of the server that owns the certificate4. FortiGate can use the subject field in the server certificate to identify the hostname of the SSL server and verify it against the client request2.


質問 # 69
Refer to the exhibit.

The global settings on a FortiGate device must be changed to align with company security policies. What does the Administrator account need to access the FortiGate global settings?

  • A. Enable two-factor authentication
  • B. Change Administrator profile
  • C. Change password
  • D. Enable restrict access to trusted hosts

正解:B


質問 # 70
Which statement regarding the firewall policy authentication timeout is true?

  • A. It is a hard timeout. The FortiGate removes the temporary policy for a user's source MAC address after this timer has expired.
  • B. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets coming from the user's source MAC.
  • C. It is an idle timeout. The FortiGate considers a user to be "idle" if it does not see any packets coming from the user's source IP.
  • D. It is a hard timeout. The FortiGate removes the temporary policy for a user's source IP address after this timer has expired.

正解:C


質問 # 71
An administrator configures FortiGuard servers as DNS servers on FortiGate using default settings.
What is true about the DNS connection to a FortiGuard server?

  • A. It uses DNS over HTTPS.
  • B. It uses DNS overTLS.
  • C. It uses UDP 53.
  • D. It uses UDP 8888.

正解:B

解説:
FortiGate Security 7.2 Study Guide (p.15): "When using FortiGuard servers for DNS, FortiOS uses DNS over TLS (DoT) by default to secure the DNS traffic." When using FortiGuard servers for DNS, FortiOS defaults to using DNS over TLS (DoT) to secure the DNS traffic1. DNS over TLS is a protocol that encrypts and authenticates DNS queries and responses using the Transport Layer Security (TLS) protocol2. This prevents eavesdropping, tampering, and spoofing of DNS data by third parties.
The default FortiGuard DNS servers are 96.45.45.45 and 96.45.46.46, and they use the hostname globalsdns.fortinet.net1. The FortiGate verifies the server hostname using the server-hostname setting in the system dns configuration1.


質問 # 72
An administrator has configured outgoing Interface any in a firewall policy. Which statement is true about the policy list view?

  • A. Interface Pair view will be disabled.
  • B. By Sequence view will be disabled.
  • C. Search option will be disabled
  • D. Policy lookup will be disabled.

正解:A

解説:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD47821


質問 # 73
If the Issuer and Subject values are the same in a digital certificate, which type of entity was the certificate issued to?

  • A. A person
  • B. A CRL
  • C. A root CA
  • D. A subordinate CA

正解:C


質問 # 74
Which statement correctly describes the use of reliable logging on FortiGate?

  • A. Reliable logging is enabled by default in all configuration scenarios.
  • B. Reliable logging can be configured only using the CLI.
  • C. Reliable logging is required to encrypt the transmission of logs.
  • D. Reliable logging prevents the loss of logs when the local disk is full.

正解:C

解説:
FortiGate Security 7.2 Study Guide (p.192): "if using reliable logging, you can encrypt communications using SSL-encrypted OFTP traffic, so when a log message is generated, it is safely transmitted across an unsecure network. You can choose the level of SSL protection used by configuring the enc-algorithm setting on the CLI."


質問 # 75
......


SAP C-HRHFC-2311 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • SAP SuccessFactors Compound Employee API
  • SAP ERP ユーザー インターフェイスと SAP SuccessFactors Employee Central の統合
トピック 2
  • SAP ERP から SAP SuccessFactors Employee Central へのコスト センターのレプリケーション、SAP SuccessFactors Employee Central から SAP ERP への組織データのレプリケーション
トピック 3
  • SAP ERP HCM システムを準備するためにカスタマイジングで行う設定を構成する
  • 適切な API をいつ使用するかを決定する
トピック 4
  • SAP SuccessFactors Employee Central と SAP ERP の統合シナリオの概要
  • SAP SuccessFactors Employee Central を使用した SAP ERP 従業員データの移行とレプリケーション

 

SAP C-HRHFC-2311問題を提供していますSAP Certified Application Associate問題集と完璧な解答付き:https://www.jpntest.com/shiken/C-HRHFC-2311-mondaishu

C-HRHFC-2311テスト問題集とオンライン試験エンジンはここにある:https://drive.google.com/open?id=1IaTHyMft0shhBH6yQ4BlZi7jkSJ8LRoc

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡