Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Professional Network Security FCSS_EFW_AD-7.6 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Refer to the exhibit, which contains a partial command output.

Question # 21

The administrator has configured BGP on FortiGate. The status of this new BGP configuration is shown in the exhibit.

What configuration must the administrator consider next?

Options:

A.

Configure a static route to 100.65.4.1.


B.

Configure the local AS to 65300.


C.

Contact the remote peer administrator to enable BGP


D.

Enable ebgp-enforce-multihop.


Expert Solution
Questions # 22:

Refer to the exhibit.

A pre-run CLI template that is used in zero-touch provisioning (ZTP) and low-touch provisioning (LTP) with FortiManager is shown.

Question # 22

The template is not assigned even though the configuration has already been installed on FortiGate.

What is true about this scenario?

Options:

A.

The administrator did not assign the template correctly when adding the model device because pre-CLI templates remain permanently assigned to the firewall


B.

Pre-run CLI templates are automatically unassigned after their initial installation


C.

Pre-run CLI templates for ZTP and LTP must be unassigned manually after the first installation to avoid conflicting error objects when importing a policy package


D.

The administrator must use post-run CLI templates that are designed for ZTP and LTP


Expert Solution
Questions # 23:

Refer to the exhibit, which shows an enterprise network connected to an internet service provider.

The administrator must configure the BGP section of FortiGate A to give internet access to the enterprise network.

Which command must the administrator use to establish a connection with the internet service provider?

Options:

A.

config neighbor


B.

config redistribute bgp


C.

config router route-map


D.

config redistribute ospf


Expert Solution
Questions # 24:

An administrator is extensively using VXLAN on FortiGate.

Which specialized acceleration hardware does FortiGate need to improve its performance?

Options:

A.

NP7


B.

SP5


C.

СР9


D.

NTurbo


Expert Solution
Questions # 25:

Refer to the exhibit, which shows the packet capture output of a three-way handshake between FortiGate and FortiManager Cloud.

What two conclusions can you draw from the exhibit? (Choose two.)

Options:

A.

FortiGate will receive a certificate that supports multiple domains because FortiManager operates in a cloud computing environment.


B.

FortiGate is connecting to the same IP server and will receive an independent certificate for its connection between FortiGate and FortiManager Cloud.


C.

If the TLS handshake contains 17 cipher suites it means the TLS version must be 1.0 on this three-way handshake.


D.

The wildcard for the domain *.fortinet-ca2.support.fortinet.com must be supported by FortiManager Cloud.


Expert Solution
Questions # 26:

Which two options should you consider to scale performance using an additional FortiGate?

Options:

A.

FGSP


B.

FGCP Active-Active


C.

VRRP


D.

FGCP Active-Passive


Expert Solution
Questions # 27:

Refer to the exhibits.

The routing tables of FortiGate_A and FortiGate_B, and a network topology are shown.

Why does FortiGate_B have only one external route available to 100.75.5.1/32?

Options:

A.

rf c-1583-compatible is not set to enable on FortiGate_B.


B.

The subnet 10.0.11.0/24 is not located in the FortiGate_B area.


C.

FortiGate_A advertises only one external route to FortiGate_B


D.

The route to 100.75.5.1/32 shown on FortiGate B has the lowest cost.


Expert Solution
Questions # 28:

How do you resolve object conflicts when importing a policy package?

Options:

A.

Rename


B.

FortiManager accept


C.

Non-default


D.

Retrieve config


Expert Solution
Questions # 29:

Refer to the exhibit, which shows the ADVPN IPsec interface representing the VPN IPsec phase 1 from Hub A to Spoke 1 and Spoke 2, and from Hub В to Spoke 3 and Spoke 4.

An administrator must configure an ADVPN using IBGP and EBGP to connect overlay network 1 with 2.

What must the administrator configure in the phase 1 VPN IPsec configuration of the ADVPN tunnels?

Options:

A.

set auto-discovery-sender enable and set network-id x


B.

set auto-discovery-forwarder enable and set remote-as x


C.

set auto-discovery-crossover enable and set enforce-multihop enable


D.

set auto-discovery-receiver enable and set npu-offload enable


Expert Solution
Questions # 30:

An administrator configured the FortiGate devices in an enterprise network to join the Fortinet Security Fabric. The administrator has a list of IP addresses that must be blocked by the data center firewall. This list is updated daily.

How can the administrator automate a firewall policy with the daily updated list?

Options:

A.

With FortiNAC


B.

With FortiAnalyzer


C.

With a Security Fabric automation


D.

With an external connector from Threat Feeds


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions