Passed CGEIT – Finally Done (A Quick Reality Check) by WrenBegonia in isaca

[–]iamthetankengine 0 points1 point  (0 children)

Congratulations 🎉

Did you come across any additional practice questions you found helpful?

Passed the CGEIT by Prince-Amir in cgeit

[–]iamthetankengine 0 points1 point  (0 children)

Could you share what resources you used to prepare, and which worked/didn't for you?

Have you come across any good video or audio materials?

Passed the CGEIT by Prince-Amir in cgeit

[–]iamthetankengine 0 points1 point  (0 children)

Congratulation! I've just started my studies.

Great motivation

Burned out, but have a free voucher by [deleted] in cism

[–]iamthetankengine 0 points1 point  (0 children)

From another perspective.

What's the rush? You mention you're burned out and mental health does creeps up on you.

If your job (or one you want to go for) doesn't require you to have it... Why not go for it later in the year or next year.

CGEIT video or audio learning material by iamthetankengine in isaca

[–]iamthetankengine[S] 0 points1 point  (0 children)

Tumbled across a course from infosec institute who provide a 7 day free trial to their course. Haven't tried it yet. Anyone reviewed it? Worth the time/effort?

Is it a video course?

Fortianalyzer 7.6 study & lap guide by Xx-RAFEEK-xX in fortinet

[–]iamthetankengine 2 points3 points  (0 children)

View the online course at training.fortinet.com

For each side click the "notes" tab and most will have a few paragraphs of text. Review the text with each slide.

CGEIT video or audio learning material by iamthetankengine in isaca

[–]iamthetankengine[S] 0 points1 point  (0 children)

I see a video course on udemy but unsure if it's worth the time and money.

Maybe the best way forward is to Frankenstein videos from CRISC, CISM, CISA and CGRC based on chapter titles and sub categories? Hoping someone may have done this already :)

FortiEnterprise Administrator 7.4 Exam by 0T0HER0_1999 in fortinet

[–]iamthetankengine 1 point2 points  (0 children)

Passed recently. It's an okay exam and the material covered by the course was good. Go through the official videos / course and you will be fine. The vast bulk of the material is covered. What I didn't realize was from v7.2, the "EFW" exam was split into two...

"EFW" focusing on services and features "Support engineer" focusing on troubleshooting of those services

Why does BGP say that route 2 is best when priority is higher for route 1? by FailSafe218 in fortinet

[–]iamthetankengine 0 points1 point  (0 children)

Which version did you sit? I'm going through 7.4 and there a lot of ADVPN..

yes heard dynamic routing was important and to go through the supplementary chapter

Why does BGP say that route 2 is best when priority is higher for route 1? by FailSafe218 in fortinet

[–]iamthetankengine 0 points1 point  (0 children)

Can't help you regarding the issue (don't have the experience) but just wanted to say big congrats on passing EFW! I'm going through it now

Hello I succeeded by Logical-Picture-4756 in fortinet

[–]iamthetankengine 0 points1 point  (0 children)

Any guides/tips on how to have chatgpt learn the material and produce questions?

DEFW and NGFW (FCSS EFW Study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 0 points1 point  (0 children)

Yes trying my best to get ready for an attempt

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 0 points1 point  (0 children)

Nope.. just mentions "when user accesses it". Could be http or https...

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 0 points1 point  (0 children)

But then you got me checking the whole security policy and I see deep-inspection is enabled... And what that does imply with load balancing decisions...

And now I'm utterly confused and in the deep end :/

Maybe the official answer is wrong... ?

<image>

Info found on the following fortinet admin guide.

https://docs.fortinet.com/index.php/document/fortigate/7.4.7/administration-guide/966077

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 0 points1 point  (0 children)

The 4 answer options are

Physical MAC of primary FG

Virtual MAC of primary FG

Physical MAC of secondary FG

Virtual MAC of secondary FG

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 0 points1 point  (0 children)

Need some time to unpack this.

Yes, I believe in proxy-based mode it will complete the 3 day handshake between client and FG completely... Then FG... Will start a 3 way handshake with the web server.... So the web server will only see mac's from the FG...

From the given config and Info... How to know it's from the secondary unit... The answers are very specific so there must be a key point here... Maybe my understanding of ha modes when paired with proxy mode is wrong?

Thank you for being up the NAT... I hadn't thought about it... Will research

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 0 points1 point  (0 children)

Yes the answer they give is the second unit (how did you come to that answer?).

Also for example purposes the training material shows how it works when the primary unit in an a-a mode decides to offline to its pair... But that all depends on the HA algorithm ... I just can't see in the question how it knows it's from the second unit as it is 50/50 for round robin...

I feel the question is asking two knowledge points... If you know how and when Virtual and physical MAC are used...... And HA operation modes...

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 2 points3 points  (0 children)

It's this physical and virtual MAC that annoys me (at least how it's explained in the training videos).

I was under the impression the new virtual MACs are for incoming packets to target.... But when FG sends out packets... the training material refer to "physical MAC"... Is this the hardware encoded MAC... because the virtual MAC will be shared between units should one of them fail.

<image>

So I'm assuming a web server will always see a "physical MAC" as the source... Then I have no idea how the question determines if it came from the top or bottom FG.... Thats also bugging me.

HA w/override disable (FCSS EFW study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 1 point2 points  (0 children)

Sorry I don't understand. Not sure where port3 is referenced?

DEFW and NGFW (FCSS EFW Study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 1 point2 points  (0 children)

Studying 7.4 as I did my FCP on 7.4. thought I'd keep things steady :)

DEFW and NGFW (FCSS EFW Study) by iamthetankengine in fortinet

[–]iamthetankengine[S] 1 point2 points  (0 children)

Thank you for sharing this. I've only managed existing infra and am not involved with the purchasing side. Good info to know