Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

A FortiGate administrator is troubleshooting a VPN that is failing to establish.

As a first step, the administrator is attempting to sniff the traffic using the command:

# diagnose sniffer packet any ‘’udp port 500 or udp port 4500 or esp’’ 4

After several minutes there is still no output. What is the most Likely reason for this?

Options:

A.

The VPN is configured to use IKE over TCP


B.

esp is not a valid sniffer argument.


C.

The ISP is blocking all VPN traffic.


D.

Mismatched IKE versions are detected on the VPN peers


Expert Solution
Questions # 22:

Refer to the exhibit.

Question # 22

If the default settings are m place, what can you conclude about the conserve mode shown in the exhibit?

Options:

A.

FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection


B.

FortiGate is currently allowing new sessions and will continue to allow sessions if memory increases another 6%.


C.

FortiGate is currently allowing now sessions that require flow-based or proxy-based content inspection, but is not performing inspection on those sessions.


D.

FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings because of high memory use.


Expert Solution
Questions # 23:

Exhibit.

Question # 23

Refer to the exhibit, which shows a partial web fillet profile configuration.

Which action does FortiGate lake if a user attempts to access www. dropbox. com, which is categorized as File Sharing and Storage?

Options:

A.

FortiGate allows the connection, based on the URL Filter configuration.


B.

FortiGate blocks the connection as an invalid URL.


C.

FortiGate exempts the connection, based on the Web Content Filter configuration.


D.

FortiGate blocks the connection, based on the FortiGuard category based filter configuration.


Expert Solution
Questions # 24:

Refer to the exhibit.

Question # 24

The sniffer log on two FortiGate devices are shown. Based on the information in the log, which two factors explain the output on FortiGate FGT-02? (Choose two answers)

Options:

A.

A third-party device is blocking protocol 50.


B.

The administrator has not yet configured the VPN tunnel on FGT-02.


C.

The administrator configured the wrong remote peer IP address on FGT-01.


D.

The administrator set the wrong sniffer filter on FGT-02.


Expert Solution
Questions # 25:

Refer to the exhibit, which shows the output of a real-time debug. Which statement about this output is true? (Choose one answer)

Question # 25

Options:

A.

The server hostname was extracted from the SNI in the client request, or from the CN in the server certificate.


B.

FortiGate found the requested URL in its local cache.


C.

This web request was inspected using the ftgd-allow web filter profile.


D.

The requested URL belongs to category ID 255.


Expert Solution
Questions # 26:

Which Iwo troubleshooting steps should you perform lf you encounter issues with intermittent web filter behavior? (Choose two.)

Options:

A.

Check that the inspection mode configured for the web filter profile matches that of the firewall policy where it is applied.


B.

Check that FortiGate is not entering conserve mode.


C.

Check that the correct port is mapped to HTTP in the Protocol Options


D.

Check that the communication between FortiGate and FortiGuard is stable


Expert Solution
Questions # 27:

Refer to the exhibit, which shows the output o! the BGP database.

Question # 27

Which two statements are correct? (Choose two.)

Options:

A.

The advertised prefix of 10.20.30.0/24 was configured using the network command.


B.

The first four prefixes are being advertised using a legacy route advertisement.


C.

The advertised prefix of 10.20.30.0/24 is being advertised through the redistribution of another routing protocol.


D.

The output shows all prefixes advertised by all neighbors as well as the local router.


Expert Solution
Questions # 28:

What is the correct order of the IKEv2 request-and-response protocol?

Options:

A.

Create_Child_SA, IKEAUTH, IKESAJNIT


B.

Create_Child_SA, IKE_SA_INIT. IKE_AUTH


C.

IKE SA INIT, IKE AUTH. Create Child SA OIKE AUTH.


D.

IKE_AUTH_IKE_SA_INIT, Create_Child_SA


Expert Solution
Questions # 29:

Exhibit.

Question # 29

Refer to the exhibit, which shows two entries that were generated in the FSSO collector agent logs.eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee

What three conclusions can you draw from these log entries? {Choose three.)

Options:

A.

Remote registry is not running on the workstation.


B.

The user ' s status shows as " not verified " in the collector agent.


C.

DNS resolution is unable to resolve the workstation name.


D.

The FortiGate firmware version is not compatible with that of the collector agent.


E.

A firewall is blocking traffic to port 139 and 445.


Expert Solution
Questions # 30:

Refer to the exhibit, which shows the partial output of a diagnose command.

Question # 30

Which two conclusions can you draw from the output shown in the exhibit? (Choose two.)

Options:

A.

FortiGate will drop the expected traffic if it does not arrive within 23 seconds.


B.

Clearing the master session has no impact on the expectation session.


C.

This is a pinhole session to allow traffic for a TCP protocol that dynamically assigns TCP ports.


D.

The session is checked against firewall policy ID 25.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions