Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which two protocol states indicate that traffic is bidirectional? (Choose two.)

Options:

A.

proto_state=01 for a TCP session.


B.

proto_state=01 for a UDP session.


C.

proto_state=05 for a TCP session.


D.

proto_state=00 for an ICMP session.


Expert Solution
Questions # 22:

Refer to the exhibit.

Partial output of a real-time OSPF debug is shown.

Question # 22

Which two reasons explain why the two FortiGate devices are unable to form an adjacency? (Choose two.)

Options:

A.

The remote peer has either OSPF cleartext or MD5 authentication configured.


B.

There is an OSPF authentication configuration mismatch.


C.

The local FortiGate does not have OSPF authentication configured


D.

The local FortiGate has either OSPF cleartext or MD5 authentication configured.


Expert Solution
Questions # 23:

Refer to the exhibit, which shows the output of diagnose sys session list.

Question # 23

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

Options:

A.

The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.


B.

Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.


C.

The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.


D.

The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.


Expert Solution
Questions # 24:

Refer to the exhibit, which shows one way communication of the downstream FortiGate with the upstream FortiGate within a Security Fabric.

Question # 24

What three actions must you take to ensure successful communication? (Choose three.)

Options:

A.

You must authorize the downstream FortiGate on the root FortiGate.


B.

FortiGate must not be in NAT mode.


C.

Ensure TCP port 8013 is not blocked along the way.


D.

You must enable Security Fabric/Fortitelemetry on the receiving interface of the upstream FortiGate.


E.

Ensure the port for Neighbor Discovery has been changed.


Expert Solution
Questions # 25:

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which two actions will FortiGate take when using the default settings for SSL certificate inspection? (Choose two answers)

Options:

A.

FortiGate uses the SNI from the user ' s web browser.


B.

FortiGate does not decrypt the traffic if the traffic is blocked by the web filter profile.


C.

FortiGate uses the CN information from the Subject field in the server certificate.


D.

FortiGate does not decrypt the traffic if the traffic is allowed by the web filter profile.


Expert Solution
Questions # 26:

Refer to the exhibit.

Question # 26

The exhibit shows the output of a session. Which two statements are correct? (Choose two.)

Options:

A.

The session did not match a firewall policy.


B.

The gateway to the destination is 10.1.10.1.


C.

The session was initiated from an authenticated user.


D.

The TCP session has been successfully established.


Expert Solution
Questions # 27:

Refer to the exhibit, which shows the output of a policy route table entry.

Question # 27

Which type of policy route does the output show?

Options:

A.

An ISDB route


B.

A regular policy route


C.

A regular policy route, which is associated with an active static route in the FIB


D.

An SD-WAN rule


Expert Solution
Questions # 28:

Exhibit.

Question # 28

Refer to the exhibit, which shows the output of a session. Which two statements are true? (Choose Iwo.)

Options:

A.

The TCP session has been successfully established.


B.

The session was initiated from an authenticated user.


C.

The session is being inspected using flow inspection.


D.

The session is being offloaded.


Expert Solution
Questions # 29:

What is an accurate description of LDAP authentication using the regular bind type?

Options:

A.

The regular bind requires the client to send the full distinguished name (ON).


B.

The regular bind type is the easiest bind type to configure on ForbOS.


C.

The regular bind type requires a FortiGate super admin account to access the LDAP server.


D.

It is not often used as a bind type


Expert Solution
Questions # 30:

Refer to the exhibit, which shows the modified output of the routing kernel.

Question # 30

Which statement is true?

Options:

A.

The egress interface associated with static route 8.8.8.8/32 is administratively up.


B.

The default static route through 10.200.1.254 is not in the forwarding information base.


C.

The default static route through port2 is in the forwarding information base.


D.

The BGP route to 10.0.4.0/24 is not in the forwarding information base.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions