Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit, which shows the partial output of command diagnose debug rating.

Question # 11

In this exhibit, which FDS server will the FortiGate algorithm choose?

Options:

A.

66.117.56.37


B.

208.91.112.194


C.

209.22.147.36


D.

64.26.151.37


Expert Solution
Questions # 12:

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.

Which action will FortiGate take when using the default settings for SSL certificate inspection?

Options:

A.

FortiGate uses the SNI from the user ' s web browser.


B.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.


C.

FortiGate uses the first entry listed in the SAN field in the server certificate.


D.

FortiGate uses the CN information from the Subject field in the server certificate.


Expert Solution
Questions # 13:

What is the diagnose test application ipsmonitor 5 command used for? (Choose one answer)

Options:

A.

To disable the IPS engine


B.

To provide information regarding IPS sessions


C.

To restart all IPS engines and monitors


D.

To enable IPS bypass mode


Expert Solution
Questions # 14:

Refer to the exhibit.

Question # 14

Partial output of the fssod daemon real-time debug command is shown. Which two conclusions can you draw from the output? (Choose two answers)

Options:

A.

FSSO cannot verify if the user is still logged in.


B.

Fortinet Single Sign-On (FSSO) is using DC Agent mode to detect logon events.


C.

FortiGate is frequently polling the workstation in case the user has logged out.


D.

FSSO is using agentless polling mode to detect logon events.


E.

FortiGate polled this event through TCP port 8000.


Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

Which route will traffic take to get to the 100.65.0.0/24 network considering the routes are all configured with the same distance?

Options:

A.

The BGP route


B.

The policy route


C.

The static route


D.

The OS PF route


Expert Solution
Questions # 16:

Exhibit.

Question # 16

Refer to the exhibit, which shows the output of a diagnose command.

What can you conclude about the debug output in this scenario?

Options:

A.

The first server provided to FortiGate when it performed a DNS query looking for a list of rating servers, was 121.111.236.179.


B.

There is a natural correlation between the value in the FortiGuard-requests field and the value in the Weight field.


C.

FortiGate used 64.26.151.37 as the initial server to validate its contract.


D.

Servers with a negative TZ value are less preferred for rating requests.


Expert Solution
Questions # 17:

Refer to the exhibit, which shows the output of the command get router info bgp neighbors 100.64.2.254 advertised-routes.

Question # 17

What can you conclude from the output?

Options:

A.

The BGP state of the two BGP participants is OpenConfirm.


B.

The router ID of the neighbor is 100.64.2.254.


C.

The BGP neighbor is advertising the 10.20.30.40/24 network to the local router.


D.

The local router is advertising the 10.20.30.40/24 network to its BGP neighbor.


Expert Solution
Questions # 18:

Question # 18

Which two observations can you make from the output? (Choose two.)

Options:

A.

The configuration was backed up


B.

A high availability (HA) failover occurred.


C.

The lest was unsuccessful.


D.

The automation stitch test is not being logged.


Expert Solution
Questions # 19:

Refer to the exhibit, which shows the partial output of a real-time OSPF debug.

Question # 19

Why are the two FortiGate devices unable to form an adjacency?

Options:

A.

The Hello packet is being sent from an OSPF router with ID 0.0.0.112.


B.

The two FortiGate devices attempting adjacency are in area 0.0.0.0.


C.

One FortiGate device is configured to require authentication, while the other is not.


D.

The passwords on the FortiGate devices do not match.


Expert Solution
Questions # 20:

Refer to the exhibit.

Question # 20

Partial output of command diagnose debug rating is shown. Which FDS server will the FortiGate algorithm choose?

Options:

A.

96.45.33.65


B.

208.91.112.194


C.

64.26.151.37


D.

209.22.147.36


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions