Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which statement about protocol options is true?

Options:

A.

Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.


B.

Protocol options give administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.


C.

Protocol options allow administrators to configure the Any setting for all enabled protocols, which provides the most efficient use of system resources.


D.

Protocol options allow administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.


Expert Solution
Questions # 2:

Exhibit.

Question # 2

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Which two statements about this debug output are correct? (Choose two.)

Options:

A.

Perfect Forward Secrecy (PFS) is enabled in the configuration.


B.

The local gateway IP address is 10.0.0.1.


C.

It shows a phase 2 negotiation.


D.

The initiator provided remote as its IPsec peer ID.


Expert Solution
Questions # 3:

The local OSPF router is unable to establish adjacency with a peer.

Which two things should the administrator do to troubleshoot the issue? (Choose two.)

Options:

A.

Check whether TCP port 179 is blocked.


B.

Check if there is an active static route to the peer.


C.

Check whether both peers have an IP address within the same subnet.


D.

Check if IP protocol 89 is blocked.


Expert Solution
Questions # 4:

Which two statements about Security Fabric communications are true? (Choose two.)

Options:

A.

FortiTelemetry and Neighbor Discovery both operate using TCP.


B.

The default port for Neighbor Discovery can be modified.


C.

FortiTelemetry must be manually enabled on the FortiGate interface.


D.

By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.


Expert Solution
Questions # 5:

Which two statements about conserve mode are true? (Choose two.)

Options:

A.

FortiGate enters conserve mode when the system memory reaches the configured extreme threshold.


B.

FortiGate starts taking the configured action for new sessions requiring content inspection when the system memory reaches the configured red threshold.


C.

FortiGate exits conserve mode when the system memory goes below the configured green threshold.


D.

FortiGate starts dropping all new sessions when the system memory reaches the configured red threshold.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

Which three pieces of information does the diagnose sys top command provide? (Choose three.)

Options:

A.

The miglogd daemon is running on CPU core ID 0.


B.

The diagnose sys top command has been running for 18 minutes.


C.

The miglogd daemon would be on top of the list, if the administrator pressed m on the keyboard.


D.

The cmdbsvr process is occupying 2.4% of the total user memory space.


E.

If the neweli daemon continues to be in the R state, it will need to be manually restarted.


Expert Solution
Questions # 7:

Exhibit.

Question # 7

Refer to the exhibit, which shows a partial web fillet profile configuration.

Which action does FortiGate lake if a user attempts to access www. dropbox. com, which is categorized as File Sharing and Storage?

Options:

A.

FortiGate allows the connection, based on the URL Filter configuration.


B.

FortiGate blocks the connection as an invalid URL.


C.

FortiGate exempts the connection, based on the Web Content Filter configuration.


D.

FortiGate blocks the connection, based on the FortiGuard category based filter configuration.


Expert Solution
Questions # 8:

Which two statements about an auxiliary session ate true? (Choose two.)

Options:

A.

With the auxiliary session selling disabled, only auxiliary sessions are offloaded.


B.

With the auxiliary session setting enabled. ECMP traffic is accelerated to the NP6 processor.


C.

With the auxiliary session setting enabled. Iwo sessions are created in case of routing change.


D.

With the auxiliary session setting disabled, for each traffic path. FortiGate uses the same auxiliary session.


Expert Solution
Questions # 9:

Which authentication option can you not configure under config user radius on FortiOS?

Options:

A.

mschap


B.

pap


C.

mschap2


D.

eap


Expert Solution
Questions # 10:

Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real-time debug? (Choose three.)

Options:

A.

Log is full on the collector agent.


B.

Inability to reach IP address of the collector agent.


C.

Refused connection. Potential mismatch of TCP port.


D.

Mismatched pre-shared password.


E.

Incompatible collector agent software version.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions