1. What are the three components of the WatchGuard System Manager software?
A) Policy Manager, Firebox System Manager (FSM), Management Server
B) Policy Manager, HostWatch, Dimension
C) Policy Manager, Firebox System Manager (FSM), HostWatch
D) Policy Manager, Report Server, Management Server
Correct Answer: C
2. Which of the following do you need to ensure you have when initially activating your firewall? Choose all that apply.
A) Firebox Serial Number
B) Feature Key
C) Account on the WatchGuard website
D) Device firmware version
Correct Answer: A and C
3. Which account do you need to log into your WatchGuard firewall through WatchGuard System Manager?
A) Admin
B) Readonly
C) Status
D) Config
Correct Answer: C
4. True or False: A Feature Key can be migrated between devices.
Correct Answer: False. A Feature Key is specific to a specific device, because it is based on the serial number.
5. What are the four types of network interfaces you can configure on your firewall?
A) External, Trusted, Optional, Custom
B) Trusted, Primary, Optional, DHCP
C) External, Optional, Trusted, Optional
D) Optional, Trusted, Custom, Internet
Correct Answer: A
6. True or False: There are three modes you can operate your firewall under: Mixed Routing, Bridged and Drop-In. Bridged mode is the default selection.
Correct Answer: False. Mixed Routing mode is the default mode.
7. What can you view directly through Firebox System Manager? Select all that apply.
A) Gateway Wireless Controller
B) Log Server
C) Traffic Monitor
D) Service Watch
Correct Answer: A, C, D
8. True or False: Through Firebox System Manager, you can run the TCP Dump command.
Correct Answer: True. This option is available under the Diagnostic Tasks tool.
9. What is the purpose of Static NAT?
A) To set the internal IP of a device to be different than the external IP.
B) To allow inbound access over a specific port.
C) To set both inbound and outbound access for a device on a specific IP.
D) To set a static IP on a device inside of your network.
Correct Answer: B
10. True or False: In order to enable NAT Loopback on your firewall, you have to configure this under the Dynamic NAT settings.
Correct Answer: False. NAT Loopback does not require anything to be enabled. You simple have to write a policy to allow it.
11. When you see the log “Unhandled Internal Packet,” what does this mean?
A) Someone inside of your network got blocked due to WebBlocker.
B) Someone outside of your network tried to send inbound traffic, but there was no policy to allow it.
C) Someone inside of your network tried to send outbound traffic, but there was no policy to allow it.
D) The firewall encountered an error when trying to review the traffic.
Correct Answer: C
12. Which of the following services utilize firewall-based Intrusion Prevention Services? Select all that apply.
A) Gateway Antivirus
B) Blocked Ports
C) IPS Service
D) Blocked Sites
Correct Answer: B and D
13. True or False: Policy precedence is most often determined by the alphabetical order of policy names.
Correct Answer: False. Policy precedence is determined by how specific the policy is in regards to what traffic is allowed.
14. In order to review the traffic that passes over you HTTP policy, what do you need to make sure to do first?
A) Turn up Diagnostic Logging under the Setup > Logging menu.
B) Turn on logging inside of WebBlocker.
C) No change needs to be made. All policies log by default.
D) Turn on Logging in the HTTP policy.
Correct Answer: D
15. True or False: A packet filter is the most secure way to pass traffic through your firewall.
Correct Answer: False. A packet filter simply reviews the header information of a packet. A proxy is what allows for more in-depth filtering of the traffic, thus providing additional security.
16. Which format would you use to block an executable file from being uploaded through FTP?
A) *exe
B) EXE
C) *EXE
D) .EXE.
Correct Answer: A
17. When adding a WebBlocker exception for *.microsoft.com/*, which sites would be allowed? Select all that apply.
A) updates.microsoft.com
B) microsoft.com/updates
C) microsoft.com/downloads
D) downloads.microsoft.com
Correct Answer: A, B, C and D
18. True or False: APT Blocker requires that Gateway Antivirus be enabled.
Correct Answer: True. APT Blocker uses the same scanning engine as APT Blocker, so the GAV service must first be enabled.
19. When implementing authentication, which service can you utilize? Pick all that apply.
A) Active Directory
B) LDAPS
C) Office 365 Single-Sign-On
D) Firebox Database
Correct Answer: A, B and D
20. When going through the initial Dimension installation, what must you make sure to do? Pick all that apply.
A) Set a static IP for the Dimension server.
B) Set an encryption password.
C) Enter the IP of all firewalls that will be logged.
D) Set up accounts for all users that will be accessing Dimension.
Correct Answer: A and B
21. True or False: In order for a Branch Office VPN to be built the Tunnel must be established first.
Correct Answer: False. The Gateway must establish first.
22. When setting up an IPSec Mobile VPN, what must you make sure to configure?
A) Virtual IP Address Pool
B) IPSec Gateway
C) Allowed Resources
D) IPSec Tunnel
Correct Answer: A and D
23. For each VLAN interface, how many untagged networks can you have?
A) One
B) Four
C) Unlimited
D) Dependent on the firewall model
Correct Answer: A
24. True or False: You can use the same VLAN ID for multiple VLANs on your firewall.
Correct Answer: False Each VLAN must have a unique ID.
25. What are the benefits of Link Aggregation? Select all that apply.
A) Allows you to bridge interfaces so your firewall can act as a switch.
B) Allows for redundancy of interfaces.
C) Creates a separate, management interface for your firewall.
D) Allows for additional throughput between your firewall and switches.
Correct Answer: B and D
26. When setting up Traffic Management on your firewall, what is the order of actions that it will be applied?
A) Policy > Application Category > Application
B) Application > Application Category > Policy
C) Application Category > Application > Policy
D) Policy > Application > Application Category
Correct Answer: B
27. Which Multi-WAN method allows you to set weights on the interfaces?
A) Round-Robin
B) Failover
C) Interface Overflow
D) Routing Table
Correct Answer: A
28. True or False: When setting up a static route, a lower metric means a lower precedence.
Correct Answer: False A lower metric indicates a higher precedence in the routing table.
29. When setting up a Firecluster, what requirements must you follow? Select all that apply.
A) Each device must be the same model.
B) Each device must have a special FireCluster subscription.
C) Each device must be activated on the WatchGuard website.
D) Each device must be running the same firmware.
Correct Answer: A, C and D
30. What is the purpose of the cluster interface?
A) To manage the Firecluster.
B) To log Firecluster events.
C) To allow the cluster members to communicate with each other.
D) To allow remote access to the Firecluster.
Correct Answer: C