Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Professional Network Security FCSS_EFW_AD-7.6 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23:ff:fc:00:86.

What two conclusions can the administrator draw? (Choose two.)

Options:

A.

The suspicious packet is related to a cluster that has VDOMs enabled.


B.

The network includes FortiGate devices configured with the FGSP protocol.


C.

The suspicious packet is related to a cluster with a group-id value lower than 255.


D.

The suspicious packet corresponds to port 7 on a FortiGate device.


Expert Solution
Questions # 2:

What action can be taken on a FortiGate to block traffic using IPS protocol decoders, focusing on network transmission patterns and application signatures?

Options:

A.

Use the DNS filter to block application signatures and protocol decoders.


B.

Use application control to limit non-URL-based software handling.


C.

Enable application detection-based SD-WAN rules.


D.

Configure a web filter profile in flow mode.


Expert Solution
Questions # 3:

Refer to the exhibit.

An HA configuration of an active-active (A-A) cluster with the same HA uptime is shown. You want HQ-NGFW-2 to handle the Core2 VDOM traffic. Which modification must you make to achieve this outcome? (Choose one answer)

Options:

A.

Reboot HQ-NGFW-2.


B.

Change the priority from 100 to 160 for HQ-NGFW-2.


C.

Change the priority from 120 to 200 for HQ-NGFW-2.


D.

Enable override in virtual cluster 2 for HQ-NGFW-2.


Expert Solution
Questions # 4:

Why is the prerun CLI template not assigned after installation?

Options:

A.

Manual removal


B.

Auto-unassigned


C.

Permanent


D.

Postrun needed


Expert Solution
Questions # 5:

Refer to the exhibit, which shows a LAN interface connected from FortiGate to two FortiSwitch devices.

What two conclusions can you draw from the corresponding LAN interface? (Choose two.)

Options:

A.

You must enable STP or RSTP on FortiGate and FortiSwitch to avoid layer 2 loopbacks.


B.

The LAN interface must use a 802.3ad type interface.


C.

This connection is using a FortiLInk to manage VLANs on FortiGate.


D.

FortiGate is using an SD-WAN-type interface to connect to a FortiSwitch device with MCLAG.


Expert Solution
Questions # 6:

Refer to the exhibit.

The routing tables of FortiGate_A and FortiGate_B are shown. FortiGate_A and FortiGate_B are in the same autonomous system.

The administrator wants to dynamically add only route 172.16.1.248/30 on FortiGate_A.

What must the administrator configure?

Options:

A.

The prefix 172.16.1.248/30 in the BGP Networks section on FortiGate_B


B.

A BGP route map out for 172.16.1.248/30 on FortiGate_B


C.

Enable Redistribute Connected in the BGP section on FortiGate_B.


D.

A BGP route map in for 172.16.1.248/30 on FortiGate_A


Expert Solution
Questions # 7:

Refer to the exhibit, which shows a corporate network and a new remote office network.

An administrator must integrate the new remote office network with the corporate enterprise network.

What must the administrator do to allow routing between the two networks?

Options:

A.

The administrator must implement BGP to inject the new remote office network into the corporate FortiGate device


B.

The administrator must configure a static route to the subnet 192.168.l.0/24 on the corporate FortiGate device.


C.

The administrator must configure virtual links on both FortiGate devices.


D.

The administrator must implement OSPF over IPsec on both FortiGate devices.


Expert Solution
Questions # 8:

Refer to the exhibits.

A policy package conflict status and information from the import device wizard in the Core1 VDOM are shown. When you import a policy package, the following message appears for the Web_restrictions web filter profile and the deep-inspection SSL-SSH profile: " The following objects were found having conflicts. Please confirm your settings, then continue. " The Web_restrictions and deep-inspection profiles are used by other FortiGate devices within FortiManager. Which step must you take to resolve the issue? (Choose one answer)

Options:

A.

Retrieve the FortiGate configuration to automatically export correct objects and policies.


B.

Create uniquely named objects on FortiGate and reimport them into the policy package.


C.

Select the FortiManager configuration that accepts changes on FortiManager and preserves existing configurations on FortiGate devices.


D.

Use non-default object values because FortiManager is unable to alter default values.


Expert Solution
Questions # 9:

Refer to the exhibit, which contains the partial output of an OSPF command.

An administrator is checking the OSPF status of a FortiGate device and receives the output shown in the exhibit.

What two conclusions can the administrator draw? (Choose two.)

Options:

A.

The FortiGate device is a backup designated router


B.

The FortiGate device is connected to multiple areas


C.

The FortiGate device injects external routing information


D.

The FortiGate device has OSPF ECMP enabled


Expert Solution
Questions # 10:

Refer to the exhibit, which shows a revision history window in the FortiManager device layer.

Question # 10

The IT team is trying to identify the administrator responsible for the most recent update in the FortiGate device database.

Which conclusion can you draw about this scenario?

Options:

A.

This retrieved process was automatically triggered by a Remote FortiGate Directly (via CLI) script.


B.

The user script_manager is an API user from the Fortinet Developer Network (FDN) retrieving a configuration.


C.

To identify the user who created the event, check it on the Configuration and Installation widget on FortiGate within the FortiManager device layer.


D.

Find the user in the FortiManager system logs and use the type=script command to find the administrator user in the user field.


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions