Pass the Fortinet Fortinet Certified Professional Network Security FCSS_EFW_AD-7.4 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit, which shows a hub and spokes deployment.

Question # 11

An administrator is deploying several spokes, including the BGP configuration for the spokes to connect to the hub.

Which two commands allow the administrator to minimize the configuration? (Choose two.)

Options:

A.

neighbor-group


B.

route-reflector-client


C.

neighbor-range


D.

ibgp-enforce-multihop


Expert Solution
Questions # 12:

Refer to the exhibit, which shows a physical topology and a traffic log.

Question # 12

The administrator is checking on FortiAnalyzer traffic from the device with IP address10.1.10.1, located behind the FortiGate ISFW device.

The firewall policy in on the ISFW device does not have UTM enabled and the administrator is surprised to see a log with the actionMalware, as shown in the exhibit.

What are the two reasons FortiAnalyzer would display this log? (Choose two.)

Options:

A.

Security rating is enabled in ISFW.


B.

ISFW is in a Security Fabric environment.


C.

ISFW is not connected to FortiAnalyzer and must go through NGFW-1.


D.

The firewall policy in NGFW-1 has UTM enabled.


Expert Solution
Questions # 13:

Refer to the exhibit, which shows an enterprise network connected to an internet service provider.

Question # 13

The administrator must configure the BGP section of FortiGate A to give internet access to the enterprise network.

Which command must the administrator use to establish a connection with the internet service provider?

Options:

A.

config neighbor


B.

config redistribute bgp


C.

config router route-map


D.

config redistribute ospf


Expert Solution
Questions # 14:

Refer to the exhibit, which shows a network diagram.

Question # 14

An administrator would like to modify the MED value advertised from FortiGate_1 to a BGP neighbor in the autonomous system 30.

What must the administrator configure on FortiGate_1 to implement this?

Options:

A.

route-map-out


B.

network-import-check


C.

prefix-list-out


D.

distribute-list-out


Expert Solution
Questions # 15:

A company's guest internet policy, operating in proxy mode, blocks access to Artificial Intelligence Technology sites using FortiGuard. However, a guest user accessed a page in this category using port 8443.

Which configuration changes are required for FortiGate to analyze HTTPS traffic on nonstandard ports like 8443 when full SSL inspection is active in the guest policy?

Options:

A.

Add a URL wildcard domain to the website CA certificate and use it in the SSL/SSH Inspection Profile.


B.

In the Protocol Port Mapping section of the SSL/SSH Inspection Profile, enter 443, 8443 to analyze both standard (443) and non-standard (8443) HTTPS ports.


C.

To analyze nonstandard ports in web filter profiles, use TLSv1.3 in the SSL/SSH Inspection Profile.


D.

Administrators can block traffic on nonstandard ports by enabling the SNI check in the SSL/SSH Inspection Profile.


Expert Solution
Questions # 16:

During the maintenance window, an administrator must sniff all the traffic going through a specific firewall policy, which is handled by NP6 interfaces. The output of the sniffer trace provides just a few packets.

Why is the output of sniffer trace limited?

Options:

A.

The traffic corresponding to the firewall policy is encrypted.


B.

auto-asic-off load is set to enable in the firewall policy,


C.

inspection-mode is set to proxy in the firewall policy.


D.

The option npudbg is not added in the diagnose sniff packet command.


Expert Solution
Questions # 17:

Refer to the exhibit, which shows theADVPNIPsec interface representing the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub В to Spoke 3 and Spoke 4.

Question # 17

An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2.

What must the administrator configure in the phase 1 VPN IPsec configuration of theADVPNtunnels?

Options:

A.

set auto-discovery-sender enable and set network-id x


B.

set auto-discovery-forwarder enable and set remote-as x


C.

set auto-discovery-crossover enable and set enforce-multihop enable


D.

set auto-discovery-receiver enable and set npu-offload enable


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions