2021 Latest WatchGuard Essentials Real Exam Dumps PDF
Essentials Exam Dumps, Essentials Practice Test Questions
Certification Path
Essential Exam is foundation level Certification, mainly designed for the network administrators. As such There is no prerequisite for this course. Anyone who is having keen interest and familiar with WatchGaurd technology are well invited to pursue this certification.
NEW QUESTION 38
Which takes precedence: WebBlocker category match or a WebBlocker exception?
- A. WebBlocker exception
- B. WebBlocker category match
Answer: B
NEW QUESTION 39
Match each type of NAT with the correct description:
Conserves IP addresses and hides the internal topology of your network. (Choose one)
- A. 1-to1 NAT
- B. Dynamic NAT
- C. NAT Loopback
Answer: C
Explanation:
Dynamic NAT is also known as IP masquerading.With dynamic NAT many computers can connect to the Internet from one public IP address. Dynamic NAT gives more security for internal hosts that use the Internet, because it hides the IP addresses of hosts on your network.
Reference:http://www.watchguard.com/help/docs/wsm/xtm_11/en-US/index.html#en-US/nat/nat_dynamic_use_c.html%3FTocPath%3DNetwork%2520Address%2520Translation%252 0(NAT)%7CAbout%2520Dynamic%2520NAT%7C_____0
NEW QUESTION 40
Match each WatchGuard Subscription Service with its function.
A repository where email messages can be sent based on analysis by spamBlocker, Gateway AntiVirus, or Data Loss Prevention. (Choose one).
- A. Gateway / Antivirus
- B. Spam Blocker
- C. Intrusion Prevention Server IPS
- D. Quarantine Server
- E. Data Loss Prevention DLP
Answer: D
Explanation:
Explanation/Reference:
The WatchGuard Quarantine Server provides a safe mechanism to quarantine any email messages that are suspected or known to be spam, or to contain viruses or sensitive data. The Quarantine Server is a repository for email messages that the SMTP proxy sends to quarantine based on analysis by spamBlocker, Gateway AntiVirus, or Data Loss Prevention.
Reference: https://www.watchguard.com/help/docs/webui/xtm_11/en-US/index.html#cshid=en-US/ quarantineserver/quar_server_about_c.html
NEW QUESTION 41
If you disable the Outgoing policy, which policies must you add to allow trusted users to connect to commonly used websites? (Select three.)
- A. NAT policy
- B. DNS port 53
- C. FTP port 21
- D. HTTPS port 443
- E. HTTP port 80
Answer: B,D,E
Explanation:
Explanation/Reference:
TCP-UDP packet filter
If you decide to remove the Outgoing policy, you must add a policy for any type of traffic you want to allow through the Firebox. If you remove the Outgoing policy and then decide you want to allow all TCP and UDP connections through the Firebox again, you must add the TCP-UDP packet filter to provide the same function.
This is because the Outgoing policy does not appear in the list of standard policies available from Policy Manager.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 97
NEW QUESTION 42
You can configure the SMTP-proxy policy to restrict email messages and email content based on which of these message characteristics? (Select four.)
- A. Check URLs in message with WebBlocker
- B. Maximum email recipients
- C. Email message size
- D. Sender Mail From address
- E. Attachment file name and content type
Answer: B,C,D,E
Explanation:
Explanation/Reference:
A: Another way to protect your SMTP server is to restrict incoming traffic to only messages that use your company domain. In this example, we use the mywatchguard.com domain. You can use your own company domain.
1. From the SMTP-Incoming Categories list, select Address > Rcpt To.
2. In the Pattern text box, type *.mywatchguard.com. Click Add. This denies any email messages with a Rcpt To address that does not match the company domain.
3. Click OK to close the SMTP Proxy Action Configuration dialog box.
C: In this exercise we will reduce the maximum email size to 5 MB (5, 000 kilobytes).
1. From the SMTP Proxy Action dialog box under the Categories list, select General > General Settings.
2. Find the Limits section. In the Set the maximum email size value box, type 5000.
D: Example: He must configure the Firebox to allow Microsoft Access database files to go through the SMTP proxy. He must also configure the Firebox to deny Apple iTunes MP4 files because of a recent vulnerability announced by Apple.
1. From the SMTP-Incoming Categories list, select Attachments > Content Types.
2. In the Actions to take section, use the None Matched drop-down list to select Allow.
This allows all content types through Firebox to the SMTP server. After Successful Company is able to add in the specific content types they want to allow, they set this parameter to strip content type that does not match their list of allowed content types.
From the SMTP-Incoming Categories list, select Attachments > Filenames.
4. The filename extension for Microsoft Access databases is ".mdb". In the list of filenames, find and select
.mdb. Click Remove. Click Yes to confirm.
3. If no rules match, the Action to take option is set to allow the attachment. In this example, MS Access files are now allowed through the Firebox.
5. In the Pattern text box, type *.mp4. Click Add.
This rule configures the Firebox to deny all files with the Apple iTunes ".mp4" file extension bound for the SMTP server.
E: The Set the maximum email recipient checkbox is used to set the maximum number of email recipients to which a message can be sent in the adjacent text box that appears, type or select the number of recipients.
The XTM device counts and allows the specified number of addresses through, and then drops the other addresses. For example, if you set the value to 50 and there is a message for 52 addresses, the first 50 addresses get the email message. The last two addresses do not get a copy of the message.
Incorrect:
Not B: Webblocker is configured through a HTTP-policy, not through an SMTP policy.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, pages 125, 126 Reference: http://watchguard.com/help/docs/wsm/xtm_11/en-us/content/en-us/proxies/smtp/ proxy_smtp_gen_settings_c.html
NEW QUESTION 43
In this diagram, which branch office VPN tunnel route must you add on the Site A Firebox to allow traffic between devices on the trusted network at Site A and the trusted network at site B? (Select one.)
- A. Local: 203.0.113.10/24 <--> Remote: 198.151.100.2/24
- B. Local: 10.0.10.0/24 <--> Remote: 192.168.1.0/24
- C. Local: 10.0.10.1/24 <--> Remote: 192.168.1.1/24
- D. Local: 192.168.1.0/24 <--> Remote: 10.0.10.0/24
Answer: C
NEW QUESTION 44
Match each WatchGuard Subscription Service with its function.
Prevents accidental or unauthorized transmission of confidential information outside your network.
(Choose one).
- A. Data Loss Prevention DLP
- B. APT Blocker
- C. Gateway / Antivirus
- D. Reputation Enable Defense RED
- E. Intrusion Prevention Server IPS
Answer: A
Explanation:
Explanation/Reference:
Data Loss Prevention (DLP) watches for accidental and intentional breaches of private/sensitive data through an organizational policy. Provides a library of over 200 rules to protect organization data and has the ability to parse over 30 different file formats including Microsoft Office formats and PDFs.
Reference: http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html
NEW QUESTION 45
What is the best method to downgrade the version of Fireware OS on your Firebox without losing all device configuration settings? (Select one.)
- A. Use the downgrade feature on Policy Manager to select a previous of Fireware OS.
- B. Change the OS compatibility setting in Policy Manager to downgrade the device. Then use Policy Manager to save the configuration to the device.
- C. Restore a saved backup image that was created for the device before the last Fireware OS upgrade.
- D. Use the Upgrade OS feature in Fireware Web UI to install the sysa_dl file for an order version of Fireware OS.
Answer: C
NEW QUESTION 46
When you configure the Global Application Control action, it is automatically applied to all policies.
- A. False
- B. True
Answer: A
NEW QUESTION 47
Match each WatchGuard Subscription Service with its function.
Cloud based service that controls access to website based on a site's previous behavior. (Choose one).
- A. WebBlocker
- B. Reputation Enable Defense RED
- C. QuarantineServer
- D. Intrusion Prevention Server IPS
- E. Data Loss Prevention DLP
- F. Application Control
Answer: B
Explanation:
Reputation Enable Device (RED) is a cloud-based reputation service that controls user's ability to get main access to web malicious sites. Works in concert with the WebBlocker module.
Reference:http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html
NEW QUESTION 48
If you disable the Outgoing policy, which policies must you add to allow trusted users to connect to commonly used websites? (Select three.)
- A. NAT policy
- B. DNS port 53
- C. FTP port 21
- D. HTTPS port 443
- E. HTTP port 80
Answer: B,D,E
Explanation:
TCP-UDP packet filter
If you decide to remove the Outgoing policy, you must add a policy for any type of traffic you want to allow through the Firebox. If you remove the Outgoing policy and then decide you want to allow all TCPand UDP connections through the Firebox again, you must add the TCP-UDP packet filter to provide the same function. This is because the Outgoing policy does not appear in the list of standard policies available from Policy Manager.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 97
NEW QUESTION 49
After you enable spamBlocker, your users experience no reduction in the amount of spam they receive. What could explain this? (Select three.)
- A. The Maximum File Size to Scan option is set too high.
- B. Connections cannot be resolved to the spamBlocker servers because DNS is not configured onthe Firebox.
- C. The spamBlocker action for Confirmed Spam is set to Allow.
- D. spamBlocker Virus Outbreak Detection is notenabled.
- E. A spamBlocker exception is configured to allow traffic fromsender *.
Answer: B,C,E
Explanation:
A: Spamblocker requires DNS to be configured on your XTM device
B: If you use spamBlocker with the POP3 proxy, you have only two actions to choose from: Add Subject Tag and Allow. Allow lets spam email messages go through theFirebox without a tag.
D: The Firebox might sometimes identify a message as spam when it is not spam. If you know the address of the sender, you can configure the Firebox with an exception that tells it not to examine messages from that source address or domain.
Reference: Fireware Basics, Courseware: WatchGuard System Manager 10, page 138
NEW QUESTION 50
Match each type of NAT with the correct description:
Conserves IP addresses and hides the internal topology of your network. (Choose one)
- A. 1-to1 NAT
- B. Dynamic NAT
- C. NAT Loopback
Answer: B
Explanation:
Explanation/Reference:
Dynamic NAT is also known as IP masquerading. With dynamic NAT many computers can connect to the Internet from one public IP address. Dynamic NAT gives more security for internal hosts that use the Internet, because it hides the IP addresses of hosts on your network.
Reference: http://www.watchguard.com/help/docs/wsm/xtm_11/en-US/index.html#en-US/nat/ nat_dynamic_use_c.html%3FTocPath%3DNetwork%2520Address%2520Translation%2520(NAT)%
7CAbout%2520Dynamic%2520NAT%7C_____0
NEW QUESTION 51
After you enable Gateway AntiVirus, IPS, or Application control, how can you make sure the services protect your network from the latest known threats? (Select one.)
- A. Configure reputation Enabled Defense.
- B. Enable HTTPS deep inspection.
- C. Enable automatic signature updates.
- D. Enable default packet handling.
Answer: C
NEW QUESTION 52
What is the best method to downgrade the version of Fireware OS on your Firebox without losing all device configuration settings? (Select one.)
- A. Use the downgrade feature on Policy Manager to select a previous of Fireware OS.
- B. Change the OS compatibility setting in Policy Manager to downgrade the device. Then use Policy Manager to save the configuration to the device.
- C. Restore a saved backup image that was created for the device before the last Fireware OS upgrade.
- D. Use the Upgrade OS feature in Fireware Web UI to install the sysa_dl file for an order version of Fireware OS.
Answer: C
NEW QUESTION 53
Match each WatchGuard Subscription Service with its function.
Prevents accidental or unauthorized transmission of confidential information outside your network. (Choose one).
- A. Data Loss Prevention DLP
- B. APT Blocker
- C. Gateway / Antivirus
- D. Reputation EnableDefense RED
- E. Intrusion Prevention Server IPS
Answer: A
Explanation:
Data Loss Prevention (DLP) watches for accidental and intentional breaches of private/sensitive data through an organizational policy. Provides a library of over 200 rules to protect organization data and has the ability to parse over 30 different file formats including Microsoft Office formats and PDFs.
Reference:http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html
NEW QUESTION 54
Match each WatchGuard Subscription Service with its function.
Controls access to website based on content categories. . (Choose one).
- A. Gateway / Antivirus
- B. Reputation Enable Defense RED
- C. Intrusion Prevention Server IPS
- D. Explanation:
WebBlocker controls access to the good and bad places that are reachable on the web,preventing users from gaining access to sites that have evil intentions.
If you configure WebBlocker to use the Websense cloud for WebBlocker lookups, WebBlocker uses the Websense content categories. A web site is added to a category when the content of the web site meets the criteria for the content category.
Reference:http://www.tomsitpro.com/articles/network-security-solutions-guide, 2-866-6.html
QUESTIONNO: 74
Match each type of NAT with the correct description:
Allows a user on the trusted or optional network to connect to a public server that is on the same physical Firebox interface by its public IP address or domain name. (Choose one)
A. 1-to1 NAT
B. Dynamic NAT
C. NAT Loopback - E. Application Control
- F. WebBlocker
Answer: F
Explanation:
NAT loopback allows a user on the trusted or optional networks to get access to a public server that is on the same physical Firebox or XTM device interface by its public IP address or domain name.
Reference:http://www.watchguard.com/help/docs/wsm/11/en-US/index_Left.html#CSHID=en-US%2Fnat%2Fnat_loopback_c.html|StartTopic=Content%2FenUS%2Fnat%2Fnat_loopback_c.html
NEW QUESTION 55
......
PDF (New 2021) Actual WatchGuard Essentials Exam Questions: https://www.prep4pass.com/Essentials_exam-braindumps.html
Dumps Moneyack Guarantee - Essentials Dumps UpTo 90% Off: https://drive.google.com/open?id=1wmDtKrUBslJ5d4msFE4HBprydXyPyQgu
