Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

Exhibit.

Question # 11

Refer to the exhibit, which shows the output of get system ha status.

NGFW-1 and NGFW-2 have been up for a week.

Which two statements about the output are true? (Choose two.)

Options:

A.

If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.


B.

If port 7 becomes disconnected on the secondary, both FortiGate devices will elect itself as primary.


C.

If FGVM...649 is rebooted. FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.


D.

If no action is taken, the primary FortiGate will leave the cluster because of the current sync status.


Expert Solution
Questions # 12:

Refer to the exhibit.

The output of a BGO debug command is shown.

Question # 12

What is the most likely reason that the local FortiGate is not receiving any prefixes from its neighbors?

Options:

A.

The local router is waiting for the keepalive message from the router 10.125.0.60.


B.

None of the three neighbors has successfully established the TCP three-way handshake with the local router.


C.

The router 100.64.3.1 is waiting for the OPEN message from the local router.


D.

The RIB-OUT configuration for router 10.127.0.75 prevents any route advertisement to the local router.


Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

Which two statements about the output are true, considering NGFW-1 and NGFW-2 have been up for a week? (Choose two.)

Options:

A.

If FGVM...649 is rebooted, FGVM...650 will become the primary FortiGate and retain that role, even after FGVM...649 rejoins the cluster.


B.

If port7 becomes disconnected on the secondary FortiGate, both FortiGate devices will elect themselves as primary.


C.

If a configuration change is made to the secondary FortiGate, the Configuration Status will not change.


D.

If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.


Expert Solution
Questions # 14:

Refer to the exhibits.

Question # 14

An OSPF peer is advertising route 172.16.52.0/24. The local FortiGate is configured with an inbound distribution list that allows the 172.16.0.0/16 network to be injected into its routing table. However, the 1 ' 2.16.52.0/24 subnet cannot be seen in the FIB.

Which two stops can the administrator of the local FortiGate take to ensure that the advertised 172.16. 52.0/24 subnet will be injected into the routing table? (Choose two.)

Options:

A.

Add another entry to the prefix list to specifically allow the 172.16.52.0/24 network.


B.

Change the ge value to 17.


C.

Change the R- value lo 16.


D.

Modify the default prefix-list behavior from implicit deny to implicit allow.


Expert Solution
Questions # 15:

What is the diagnose test application ipsmonitor 5 command used for? (Choose one answer)

Options:

A.

To disable the IPS engine


B.

To provide information regarding IPS sessions


C.

To restart all IPS engines and monitors


D.

To enable IPS bypass mode


Expert Solution
Questions # 16:

What is an accurate description of LDAP authentication using the regular bind type?

Options:

A.

The regular bind requires the client to send the full distinguished name (ON).


B.

The regular bind type is the easiest bind type to configure on ForbOS.


C.

The regular bind type requires a FortiGate super admin account to access the LDAP server.


D.

It is not often used as a bind type


Expert Solution
Questions # 17:

Refer to the exhibit, which shows the output of get router info bgp summary.

Question # 17

Which two statements are true? (Choose two.)

Options:

A.

The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.


B.

The TCP connection with BGP neighbor 100.64.2.254 was successful.


C.

The local FortiGate has received 18 packets from a BGP neighbor.


D.

The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264


Expert Solution
Questions # 18:

In the SAML negotiation process, which section does the Identity Provider (IdP) provide the SAML attributes utilized in the authentication process to the Service Provider (SP)?

Options:

A.

SP Login dump


B.

Authentication Response


C.

Authentication Request


D.

Assertion dump


Expert Solution
Questions # 19:

Refer to the exhibit, which shows a partial output of the fssod daemon real-time debug command.

Question # 19

What two conclusions can you draw from the output? (Choose two.)

Options:

A.

The workstation with IP 10.124.2.90 will be polled frequently using TCP port 445 to see if the user is still logged on.


B.

The logon event can be seen on the collector agent installed on Windows.


C.

FSSO is using DC agent mode to detect logon events.


D.

FSSO is using agentless polling mode to detect logon events.


Expert Solution
Questions # 20:

Refer to the exhibit, which shows a partial web filter profile configuration.

Question # 20

The URL www.dropbox.com is categorized as File Sharing and Storage.

Which action does FortiGate take if a user attempts to access www.dropbox.com?

Options:

A.

FortiGate blocks the connection as an invalid URL.


B.

Based on the URL Filter configuration, FortiGate allows the connection.


C.

FortiGate blocks the connection, based on the FortiGuard category-based filter configuration.


D.

Based on the Web Content filter configuration, access to www.dropbox.com would be exempted.


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions