Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Exhibit.

Question # 11

Refer to the exhibit, which shows a partial web fillet profile configuration.

Which action does FortiGate lake if a user attempts to access www. dropbox. com, which is categorized as File Sharing and Storage?

Options:

A.

FortiGate allows the connection, based on the URL Filter configuration.


B.

FortiGate blocks the connection as an invalid URL.


C.

FortiGate exempts the connection, based on the Web Content Filter configuration.


D.

FortiGate blocks the connection, based on the FortiGuard category based filter configuration.


Expert Solution
Questions # 12:

Refer to the exhibit, which shows the output of get router info ospf neighbor.

Question # 12

What can you conclude from the command output?

Options:

A.

The network type connecting the local Fortigate and OSPF neighbor 0.0.0.10 is point-to-point.


B.

All neighbors are in area 0.0.0.0.


C.

The local FortiGate is the BDR.


D.

The local FortiGate is not a DROther.


Expert Solution
Questions # 13:

In a Security Fabric environment which three actions must you take to ensure successful communication among the nodes? (Choose three.)

Options:

A.

You must ensure that TCP port 8013 is not blocked along the way.


B.

You must ensure that the port for Neighbor Discovery has been changed.


C.

You must configure FortiGate in transparent mode.


D.

You must authorize the downstream FortiGate on the root FortiGate.


E.

You must enable FortiTelemetry on the receiving interlace of the upstream FortiGate.


Expert Solution
Questions # 14:

In IKEv2, which exchange establishes the first CHILD_SA?

Options:

A.

IKE_SA_INIT


B.

INFORMATIONAL


C.

CREATE_CHILD_SA


D.

IKE_Auth


Expert Solution
Questions # 15:

Refer to the exhibits.

Question # 15

FGT-1 is an area border router (ABR) that has interfaces in OSPF areas 0.0.0.0 and 0.0.0.5. FGT-3 acts as an autonomous system border router (ASBR), importing static routes into OSPF. FGT-2 is an internal router with all its interfaces belonging to area 0.0.0.5. FGT-1 is receiving all advertised routes from FGT-2, however, FGT-3 is not receiving any of the advertised routes from FGT-1. What is the most likely reason for this? (Choose one answer)

Options:

A.

Area 0.0.0.5 is configured not to propagate type 5 LSAs.


B.

FGT-2 is configured with a distribution list to block all advertised routes from FGT-3.


C.

FGT-3 and FGT-2 have not formed an OSPF adjacency yet.


D.

IP protocol 89 is blocked between FGT-1 and FGT-3.


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

If the default settings are m place, what can you conclude about the conserve mode shown in the exhibit?

Options:

A.

FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection


B.

FortiGate is currently allowing new sessions and will continue to allow sessions if memory increases another 6%.


C.

FortiGate is currently allowing now sessions that require flow-based or proxy-based content inspection, but is not performing inspection on those sessions.


D.

FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings because of high memory use.


Expert Solution
Questions # 17:

Refer to the exhibit.

Question # 17

Which two observations can you make about the web filter traffic captured using the flow tool? (Choose two.)

Options:

A.

The session is offloaded to the NPU.


B.

The firewall policy is configured with proxy-based inspection mode.


C.

The web filter profile is configured with proxy-based inspection mode.


D.

The HTTPS port is mapped to 443 in the SSL/SSH Inspection Profile


Expert Solution
Questions # 18:

Refer to the exhibit.

The exhibit shows the output from using the command diagnose debug application samld -1 to diagnose a SAML connection.

Question # 18

Based on this output, what can you conclude?

Options:

A.

Active Directory is used for authentication.


B.

The authentication request is for an SSL VPN connection.


C.

The IdP IP address is 10.1.10.254.


D.

The IdP IP address is 10.1.10.2.


Expert Solution
Questions # 19:

Refer to the exhibit, which shows the partial output of a real-time OSPF debug.

Question # 19

Why are the two FortiGate devices unable to form an adjacency?

Options:

A.

The Hello packet is being sent from an OSPF router with ID 0.0.0.112.


B.

The two FortiGate devices attempting adjacency are in area 0.0.0.0.


C.

One FortiGate device is configured to require authentication, while the other is not.


D.

The passwords on the FortiGate devices do not match.


Expert Solution
Questions # 20:

What are two reasons that an OSPF router does not have any type 5 tank-state advertisements (LSAs) In its link-stale database (LSD6)? (Choose two.)

Options:

A.

There is no autonomous system border router (ASBR) in the network,


B.

The peer of the local router is using a prefix-list-out. configuration to prevent all type 5 LSAs to be advertised.


C.

The local router is located in a stub area


D.

IP protocol 89 is blocked between the local router and its peer.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions