Latest 2022 Realistic Verified Essentials Dumps - 100% Free Essentials Exam Dumps [Q11-Q35]

Share

Latest 2022 Realistic Verified Essentials Dumps - 100% Free Essentials Exam Dumps

Get 2022 Updated Free WatchGuard Essentials Exam Questions & Answer

NEW QUESTION 11
When your device is in a default state, to which interface do you connect your management computer so you can use the Quick Setup Wizard or Web Setup Wizard to configure the device? (Select one.)

  • A. Any interface
  • B. Console interface
  • C. Interface 1
  • D. Interface 0

Answer: C

Explanation:
To start the Web Setup Wizard, connect your computer to interface number 1 of your XTMdevice with an Ethernet cable. This is the trusted interface.
Reference:http://www.watchguard.com/help/docs/wsm/xtm_11/en-US/index.html#en-US/installation/qsw_web_about_c.html

 

NEW QUESTION 12
Match each WatchGuard Subscription Service with its function.
Uses full-system emulation analysis to identify characteristics and behavior of zero-day malware. (Choose one).

  • A. DataLoss Prevention DLP
  • B. WebBlocker
  • C. Gateway / Antivirus
  • D. Quarantine Server
  • E. Reputation Enable Defense RED
  • F. Spam Blocker
  • G. Intrusion Prevention Server IPS
  • H. Application Control
  • I. APT Blocker

Answer: I

Explanation:
APT Blocker is intended to stop malware and zero-day threats that are trying to invade anorganization's network.
APT Blocker uses a next-gen sandbox to get detailed views into the execution of a malware program. After first running through other security services, files are fingerprinted and checked against an existing database - first on theappliance and then in the cloud. If the file has never been seen before, it is analyzed using the system emulator, which monitors the execution of all instructions. It can spot the evasion techniques that other sandboxes miss.
Reference:http://www.watchguard.com/wgrd-products/security-modules/apt-blocker

 

NEW QUESTION 13
Which of these options are private IPv4 addresses you can assign to a trusted interface, as described in RFC 1918, Address Allocation for Private Internets? (Select three.)

  • A. 192.168.50.1/24
  • B. 192.0.2.1/24
  • C. 10.50.1.1/16
  • D. 172.16.0.1/16
  • E. 198.51.100.1/24

Answer: A,C,D

 

NEW QUESTION 14
Which tool can add an IP address for the Firebox to permanently block? (Select one)

  • A. Log Server
  • B. Firebox System Manager - Authentication list
  • C. Traffic Monitor
  • D. Firebox System Manager - Subscription services
  • E. FireWatch
  • F. FireBox System Manager - Blocked Sites list

Answer: B

Explanation:
Block a site permanently
The Successful Company networkadministrator has been driven to distraction recently by a script kiddy using addresses in the 192.136.15.0/24 network to run probes of the Successful network. In this exercise, we permanently block all connections from that network.
1.From PolicyManager, select Setup > Default Threat Protection > Blocked Sites. The Blocked Sites Configuration dialog box opens.
2.On the Blocked Sites tab, click Add.
3.The Add Site dialog box opens. 3. Use the Choose Type drop-down list to select Network IP. In the Value text box, type 192.136.15.0/ 24.
4. Click OK.
The entry appears in the Blocked Sites list. With this configuration, the Firebox blocks all packets to and from the 192.136.15.0/24 network range.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181

 

NEW QUESTION 15
You configured four Device Administrator user accounts for your Firebox. To see a report of witch Device Management users have made changes to the device configuration, what must you do? (Select two.)

  • A. Start Firebox System Manager for the device and review the activity for the Management Users on the Authentication List tab.
  • B. Open WatchGuard Server Center and review the configuration history for managed devices.
  • C. Connect to Report Manager or Dimension and view the Audit Trail report for your device.
  • D. Configure your device to send audit trail log messages to your WatchGuard Log Server or Dimension Log Server.

Answer: B,C

 

NEW QUESTION 16
Which takes precedence: WebBlocker category match or a WebBlocker exception?

  • A. WebBlocker exception
  • B. WebBlocker category match

Answer: B

 

NEW QUESTION 17
You can configure your Firebox to send log messages to how many WatchGuard Log Servers at the same time? (Select one.)

  • A. One
  • B. As many as you have configured on your network.
  • C. Two

Answer: C

 

NEW QUESTION 18
From the Firebox System Manager >Authentication List tab, you can view all of the authenticated users connected to your Firebox and disconnect any of them.

  • A. False
  • B. True

Answer: B

Explanation:
http://www.watchguard.com/help/docs/wsm/xtm_11/en-us/content/en-us/fsm/authentic_users_wsm.html

 

NEW QUESTION 19
For which of these third party authentication methods must you specify a search base? (Select two.)

  • A. LDAP
  • B. Active Directory
  • C. RADIUS
  • D. SecurID

Answer: A,B

Explanation:
Explanation/Reference:
B: Configuring the Firebox to use Active Directory authentication is similar to the process for LDAP authentication. You must set a search base to put limits on the directories on the authentication server the Firebox searches in for an authentication match.
D: When you configure the Firebox to use LDAP authentication, you must set a search base to put limits on the directories on the authentication server the Firebox searches in for an authentication match Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 83-84

 

NEW QUESTION 20
You can configure the SMTP-proxy policy to restrict email messages and email content based on which of these message characteristics? (Select four.)

  • A. Check URLs in message with WebBlocker
  • B. Maximum email recipients
  • C. Email message size
  • D. Sender Mail From address
  • E. Attachment file name and content type

Answer: B,C,D,E

Explanation:
Explanation/Reference:
A: Another way to protect your SMTP server is to restrict incoming traffic to only messages that use your company domain. In this example, we use the mywatchguard.com domain. You can use your own company domain.
1. From the SMTP-Incoming Categories list, select Address > Rcpt To.
2. In the Pattern text box, type *.mywatchguard.com. Click Add. This denies any email messages with a Rcpt To address that does not match the company domain.
3. Click OK to close the SMTP Proxy Action Configuration dialog box.
C: In this exercise we will reduce the maximum email size to 5 MB (5, 000 kilobytes).
1. From the SMTP Proxy Action dialog box under the Categories list, select General > General Settings.
2. Find the Limits section. In the Set the maximum email size value box, type 5000.
D: Example: He must configure the Firebox to allow Microsoft Access database files to go through the SMTP proxy. He must also configure the Firebox to deny Apple iTunes MP4 files because of a recent vulnerability announced by Apple.
1. From the SMTP-Incoming Categories list, select Attachments > Content Types.
2. In the Actions to take section, use the None Matched drop-down list to select Allow.
This allows all content types through Firebox to the SMTP server. After Successful Company is able to add in the specific content types they want to allow, they set this parameter to strip content type that does not match their list of allowed content types.
From the SMTP-Incoming Categories list, select Attachments > Filenames.
4. The filename extension for Microsoft Access databases is ".mdb". In the list of filenames, find and select
.mdb. Click Remove. Click Yes to confirm.
3. If no rules match, the Action to take option is set to allow the attachment. In this example, MS Access files are now allowed through the Firebox.
5. In the Pattern text box, type *.mp4. Click Add.
This rule configures the Firebox to deny all files with the Apple iTunes ".mp4" file extension bound for the SMTP server.
E: The Set the maximum email recipient checkbox is used to set the maximum number of email recipients to which a message can be sent in the adjacent text box that appears, type or select the number of recipients.
The XTM device counts and allows the specified number of addresses through, and then drops the other addresses. For example, if you set the value to 50 and there is a message for 52 addresses, the first 50 addresses get the email message. The last two addresses do not get a copy of the message.
Incorrect:
Not B: Webblocker is configured through a HTTP-policy, not through an SMTP policy.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 125, 126 Reference: http://watchguard.com/help/docs/wsm/xtm_11/en-us/content/en-us/proxies/smtp/ proxy_smtp_gen_settings_c.html

 

NEW QUESTION 21
The policies in a default Firebox configuration do not allow outgoing traffic from optional interfaces.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 22
Match each WatchGuard Subscription Service with its function.
Cloud based service that controls access to website based on a site's previous behavior. (Choose one).

  • A. WebBlocker
  • B. Reputation Enable Defense RED
  • C. QuarantineServer
  • D. Intrusion Prevention Server IPS
  • E. Data Loss Prevention DLP
  • F. Application Control

Answer: B

Explanation:
Reputation Enable Device (RED) is a cloud-based reputation service that controls user's ability to get main access to web malicious sites. Works in concert with the WebBlocker module.
Reference:http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html

 

NEW QUESTION 23
Match the monitoring tool to the correct task.
Which tool can learn the status of your IPS signature database? (Select one)

  • A. Log Server
  • B. Traffic Monitor
  • C. FireWatch
  • D. FireBox System Manager - Blocked Sites list
  • E. Firebox System Manager - Subscription services
  • F. Firebox System Manager - Authentication list

Answer: E

Explanation:
To look up information about an IPS signature:
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 15, 34, 59, 181

 

NEW QUESTION 24
Which of these options are private IPv4 addresses you can assign to a trusted interface, as described in RFC 1918, Address Allocation for Private Internets? (Select three.)

  • A. 192.168.50.1/24
  • B. 192.0.2.1/24
  • C. 10.50.1.1/16
  • D. 172.16.0.1/16
  • E. 198.51.100.1/24

Answer: A,C,D

 

NEW QUESTION 25
The IP address for the trusted interface on your Firebox is 10.0.40.1/24, but you want to change the IP address for this interface. How can you avoid a network outage for clients on the trusted network when you change the interface IP address to 10.0.50.1/24? (Select one.)

  • A. Add 10.0.40.1/24 as a secondary IP address for the interface.
  • B. Add a route to 10.0.40.0/24 with the gateway 10.0.50.1.
  • C. Create a 1-to-1 NAT rule for traffic from the 10.0.40.0/24 subnet to addresses on the 10.0.50.0/24 subnet.
  • D. Add IP addresses on the 10.0.40.0/24 subnet to the DHCP Server IP address pool for this interface.

Answer: A

 

NEW QUESTION 26
Which policies can use the Intrusion Prevention Service to block network attacks? (Select one?)

  • A. Only proxy policies
  • B. Only packet filter policies
  • C. Only inbound policies
  • D. Only HTTP and HTTPS Proxy policies
  • E. All policies

Answer: E

 

NEW QUESTION 27
Match each WatchGuard Subscription Service with its function.
Prevents accidental or unauthorized transmission of confidential information outside your network.
(Choose one).

  • A. Data Loss Prevention DLP
  • B. APT Blocker
  • C. Gateway / Antivirus
  • D. Reputation Enable Defense RED
  • E. Intrusion Prevention Server IPS

Answer: A

Explanation:
Explanation/Reference:
Data Loss Prevention (DLP) watches for accidental and intentional breaches of private/sensitive data through an organizational policy. Provides a library of over 200 rules to protect organization data and has the ability to parse over 30 different file formats including Microsoft Office formats and PDFs.
Reference: http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html

 

NEW QUESTION 28
With the policies configured as shown in this image, HTTP traffic can be sent and received through branch office VPN tunnel.1 and tunnel.2.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 29
From the Firebox System Manager >Authentication List tab, you can view all of the authenticated users connected to your Firebox and disconnect any of them.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 30
In this diagram, which branch office VPN tunnel route must you add on the Site A Firebox to allow traffic between devices on the trusted network at Site A and the trusted network at site B? (Select one.)

  • A. Local: 203.0.113.10/24 <--> Remote: 198.151.100.2/24
  • B. Local: 10.0.10.0/24 <--> Remote: 192.168.1.0/24
  • C. Local: 10.0.10.1/24 <--> Remote: 192.168.1.1/24
  • D. Local: 192.168.1.0/24 <--> Remote: 10.0.10.0/24

Answer: C

Explanation:
The local, Site A, network is 10.0.10.1/24 while the remote, Site B, network is 192.168.1.1/24.

 

NEW QUESTION 31
Which takes precedence: WebBlocker category match or a WebBlocker exception?

  • A. WebBlocker exception
  • B. WebBlocker category match

Answer: A

 

NEW QUESTION 32
How is a proxy policy different from a packet filter policy? (Select two.)

  • A. Only a proxy policy uses the IP source,destination, and port to control network traffic.
  • B. Only a proxy policy can prevent specific threats without blocking the entire connection.
  • C. Only a proxy works at the application, network, and transport layers to examine all connection data.
  • D. Only a proxy policy examines information in the IP header.

Answer: B,C

Explanation:
C: Proxies can prevent potential threats from reaching your network without blocking the entire connection.
D: A proxy operates at the application layer, as well as the network and transport layers of a TCP/IP packet, while a packet filter operates onlyat the network and transport protocol layers.
Incorrect:
Not A: A packet filter examines each packet's IP header to control the network traffic into and out of your network.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 95

 

NEW QUESTION 33
Match each type of NAT with the correct description:
Conserves IP addresses and hides the internal topology of your network. (Choose one)

  • A. 1-to1 NAT
  • B. Dynamic NAT
  • C. NAT Loopback

Answer: C

Explanation:
Dynamic NAT is also known as IP masquerading.With dynamic NAT many computers can connect to the Internet from one public IP address. Dynamic NAT gives more security for internal hosts that use the Internet, because it hides the IP addresses of hosts on your network.
Reference:http://www.watchguard.com/help/docs/wsm/xtm_11/en-US/index.html#en-US/nat/nat_dynamic_use_c.html%3FTocPath%3DNetwork%2520Address%2520Translation%252 0(NAT)%7CAbout%2520Dynamic%2520NAT%7C_____0

 

NEW QUESTION 34
If you disable the Outgoing policy, which policies must you add to allow trusted users to connect to commonly used websites? (Select three.)

  • A. NAT policy
  • B. DNS port 53
  • C. FTP port 21
  • D. HTTPS port 443
  • E. HTTP port 80

Answer: B,D,E

Explanation:
Explanation/Reference:
TCP-UDP packet filter
If you decide to remove the Outgoing policy, you must add a policy for any type of traffic you want to allow through the Firebox. If you remove the Outgoing policy and then decide you want to allow all TCP and UDP connections through the Firebox again, you must add the TCP-UDP packet filter to provide the same function. This is because the Outgoing policy does not appear in the list of standard policies available from Policy Manager.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 97

 

NEW QUESTION 35
......


Understanding functional and technical aspects of Essentials Authentication and VPNs

The following will be discussed here:

  • BOVPN virtual interfaces
  • Users and groups in policies
  • Firebox authentication portal
  • Understand user authentication and VPN settings on the Firebox
  • Mobile VPN routing options and protocols
  • Branch Office VPN gateways and tunnel routes
  • Authentication servers
  • Branch Office VPN and NAT

Understanding functional and technical aspects of Essentials Monitoring, Logging, and Reporting

The following will be discussed here:

  • Tools to monitor Firebox status and activity
  • Logging settings
  • Firebox log messages
  • Firebox logging to Dimension or WatchGuard Cloud
  • Understand how to use management tools to monitor or troubleshoot a Firebox.
  • Diagnostic tools in Firebox System Manager

 

Essentials Dumps PDF and Test Engine Exam Questions: https://www.examprepaway.com/WatchGuard/braindumps.Essentials.ete.file.html

Get New Essentials Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1aIOmWQ6Q0Q4vKgv_1wT3Znq9wVIKW-Ft