Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit, which shows a partial output of the real-time LDAP debug.

Question # 1

What two actions can the administrator take to resolve this issue? (Choose two.)

Options:

A.

Ensure the user logs in using ' John Smith ' not ' jsmith ' .


B.

Ensure the user is providing the correct user credentials.


C.

Ensure the user is a member of at least one AD group to ensure step 4 of the LDAP authentication process is successful.


D.

Ensure the account is active.


Expert Solution
Questions # 2:

Refer to the exhibit, which shows the output of get router info ospf neighbor.

Question # 2

What can you conclude from the command output?

Options:

A.

The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.


B.

All neighbors are in area 0.0.0.0.


C.

The local FortiGate is the BDR.


D.

The local FortiGate is not a DROther.


Expert Solution
Questions # 3:

Which statement about parallel path processing is correct (PPP)?

Options:

A.

PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.


B.

Only FortiGate hardware configurations affect the path that a packet takes.


C.

PPP does not apply to packets that are part of an already established session.


D.

Software configuration has no impact on PPP.


Expert Solution
Questions # 4:

Refer to the exhibit.

Question # 4

Which two observations can you make about the web filter traffic captured using the flow tool? (Choose two.)

Options:

A.

The session is offloaded to the NPU.


B.

The firewall policy is configured with proxy-based inspection mode.


C.

The web filter profile is configured with proxy-based inspection mode.


D.

The HTTPS port is mapped to 443 in the SSL/SSH Inspection Profile


Expert Solution
Questions # 5:

Refer to the exhibit.

Question # 5

The output of diagnose sys session list command is shown.

If the HA ID for the primary device is 9, what happens if the primary fails and the secondary becomes the primary?

Options:

A.

The session is synchronized with the secondary device, however, because application control is applied. the session is marked dirty and has to be reevaluated after failover.


B.

The session will be removed from the session table of the secondary device because the TCP session is not yet fully established.


C.

The session continues to permit traffic on the new primary device after failover. without requiring the client to restart the session with the server.


D.

The session state is preserved but the kernel will re-evaluate the session because the routing information will be flushed


Expert Solution
Questions # 6:

Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real-time debug? (Choose three.)

Options:

A.

The SSL certificate used for FSSO over SSL has expired.


B.

The connection was refused. There may be a mismatch of the TCP port.


C.

FortiGate cannot reach the IP address of the collector agent.


D.

The pro-shared key does not match


E.

The group filters do not match.


Expert Solution
Questions # 7:

Refer to the exhibit, which shows the output of a debug command.

Question # 7

Which two statements about the output are true? (Choose two.)

Options:

A.

The interlace is part of the OSPF backbone area.


B.

There are a total of five OSPF routers attached to the vorz4 network segment


C.

One of the neighbors has a router ID of 0.0.0.4.


D.

In the network connected to port4, two OSPF routers are down.


Expert Solution
Questions # 8:

What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?

Options:

A.

A mismatched proposal was detected during the IKE_AUTH exchange.


B.

A mismatched Diffie-Hellman group was detected during the IKE_SA_INIT exchange.


C.

A mismatched pre-shared key was detected during the IKE_AUTH exchange.


D.

Mismatched quick-mode selectors were detected during the CREATE_CHILD_SA exchange.


Expert Solution
Questions # 9:

What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?

Options:

A.

Mismatched traffic selectors (phase 2 / “quick-mode selectors”) were detected during the CREATE_CHILD_SA exchange.


B.

A mismatched proposal was detected during the IKE_AUTH exchange.


C.

A mismatched pre-shared key was detected during the IKE_AUTH exchange.


D.

A mismatched Diffie-Hellman group was detected during the IKE_SA_INIT exchange.


Expert Solution
Questions # 10:

Refer to the exhibit, which shows the partial output of a diagnose command.

Question # 10

Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)

Options:

A.

FortiGate will drop the expected traffic if it does not arrive within 23 seconds.


B.

Clearing the master session has no impact on the expectation session.


C.

This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.


D.

The session is checked against firewall policy ID 25.


Expert Solution
Viewing page 1 out of 4 pages
Viewing questions 1-10 out of questions