Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Partial output of diagnose sys session stat command is shown.

Question # 1

An administrator has noticed unusual behavior from FortiGate. It appears that sessions are randomly removed. Which two reasons could explain this? (Choose two.)

Options:

A.

FortiGate is deleting sessions because the kernel cannot allocate more memory pages


B.

FortiGate is dropping all TCP sessions with incomplete three-way handshakes.


C.

FortiGate is not accepting sessions because the device has been down 10 out of 120 seconds.


D.

FortiGate is flushing sessions because of high memory usage.


Expert Solution
Questions # 2:

While troubleshooting a FortiGate web filter issue, users report that they cannot access any websites, even though those sites are not explicitly blocked by any web filter profiles that are applied to firewall policies.

Question # 2

What are the three most likely reasons for this behavior? (Choose three answers)

Options:

A.

The web filter cache has been cleared causing all websites to take longer to be rated.


B.

The SSL/TLS deep inspection was configured but the browsers do not have the FortiGate certificate installed.


C.

The webfilter-force-off setting has been enabled under config system fortiguard.


D.

The DNS server is unreachable, preventing URL resolution.


E.

The FortiGuard Web Filtering license has expired, causing FortiGate to apply the default block action.


Expert Solution
Questions # 3:

A FortiGate administrator is troubleshooting a VPN that is failing to establish.

As a first step, the administrator is attempting to sniff the traffic using the command:

# diagnose sniffer packet any ‘’udp port 500 or udp port 4500 or esp’’ 4

After several minutes there is still no output. What is the most Likely reason for this?

Options:

A.

The VPN is configured to use IKE over TCP


B.

esp is not a valid sniffer argument.


C.

The ISP is blocking all VPN traffic.


D.

Mismatched IKE versions are detected on the VPN peers


Expert Solution
Questions # 4:

Refer to the exhibit, which shows the partial output of FortiOS kernel slabs.

Question # 4

Which statement is true?

Options:

A.

The total slab size of the sctp_session slab is 0 kB and is associated with the user space.


B.

The total slab size of the ip_session slab is 3600 kB and is associated with the user space.


C.

The total slab size of the ip6_session slab is 1300 kB and is associated with the kernel.


D.

The total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.


Expert Solution
Questions # 5:

Refer to the exhibit, which shows the output of diagnose sys session list.

Question # 5

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

Options:

A.

The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.


B.

Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.


C.

The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.


D.

The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

The administrator did not override the FortiGuard FODN or IP address in the FortiGate configuration

Which IP address did FortiGate get when resolving the servicem,fortiguard.net name?

Options:

A.

208.91.112.194


B.

209.22.147.36


C.

64.26.151.37


D.

96.45.33.65


Expert Solution
Questions # 7:

Which statement about IKEv2 is true?

Options:

A.

Both IKEv1 and IKEv2 share the feature of asymmetric authentication.


B.

IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.


C.

IKEv1 and IKEv2 use same TCP port but run on different UDP ports.


D.

IKEv1 and IKEv2 share the concept of phase1 and phase2.


Expert Solution
Questions # 8:

Refer to the exhibit, which shows the output o! the BGP database.

Question # 8

Which two statements are correct? (Choose two.)

Options:

A.

The advertised prefix of 10.20.30.0/24 was configured using the network command.


B.

The first four prefixes are being advertised using a legacy route advertisement.


C.

The advertised prefix of 10.20.30.0/24 is being advertised through the redistribution of another routing protocol.


D.

The output shows all prefixes advertised by all neighbors as well as the local router.


Expert Solution
Questions # 9:

Refer to the exhibit, which shows the output of a debug command.

Question # 9

Which two statements about the output are true? (Choose two.)

Options:

A.

The interlace is part of the OSPF backbone area.


B.

There are a total of five OSPF routers attached to the vorz4 network segment


C.

One of the neighbors has a router ID of 0.0.0.4.


D.

In the network connected to port4, two OSPF routers are down.


Expert Solution
Questions # 10:

What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two.)

Options:

A.

Packet was dropped because of policy route misconfiguration.


B.

Packet was dropped because of traffic shaping.


C.

Trusted host list misconfiguration.


D.

VIP or IP pool misconfiguration.


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions