Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.

Which action will FortiGate take when using the default settings for SSL certificate inspection?

Options:

A.

FortiGate uses the SNI from the user's web browser.


B.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.


C.

FortiGate uses the first entry listed in the SAN field in the server certificate.


D.

FortiGate uses the CN information from the Subject field in the server certificate.


Expert Solution
Questions # 22:

Refer to the exhibit, which shows the modified output of the routing kernel.

Question # 22

Which statement is true?

Options:

A.

The egress interface associated with static route 8.8.8.8/32 is administratively up.


B.

The default static route through 10.200.1.254 is not in the forwarding information base.


C.

The default static route through port2 is in the forwarding information base.


D.

The BGP route to 10.0.4.0/24 is not in the forwarding information base.


Expert Solution
Questions # 23:

Which two statements about Security Fabric communications are true? (Choose two.)

Options:

A.

FortiTelemetry and Neighbor Discovery both operate using TCP.


B.

The default port for Neighbor Discovery can be modified.


C.

FortiTelemetry must be manually enabled on the FortiGate interface.


D.

By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.


Expert Solution
Questions # 24:

Refer to the exhibit, which contains the output of diagnose vpn tunnel list.

Question # 24

Which command will capture ESP traffic for the VPN named DialUp_0?

Options:

A.

diagnose sniffer packet any 'ip proto 50'


B.

diagnose sniffer packet any 'host 10.0.10.10'


C.

diagnose sniffer packet any 'esp and host 10.200.3.2'


D.

diagnose sniffer packet any 'port 4500'


Expert Solution
Questions # 25:

Refer to the exhibit, which shows the output of a BGP debug command.

Question # 25

What can you conclude about the router in this scenario?

Options:

A.

The router 100.64.3.1 needs to update the local AS number in its BGP configuration in order to bring up the 8GP session with the local router.


B.

An inbound route-map on local router is blocking the prefixes from neighbor 100.64.3.1.


C.

All of the neighbors displayed are part of a single BGP configuration on the local router with the neighbor-range set to a value of 4.


D.

The BGP session with peer 10.127.0.75 is up.


Expert Solution
Questions # 26:

Refer to the exhibit.

Question # 26

A partial output of diagnose npu up6 port-list on FortiGate 2000E is shown.

An administrator is unable to analyze traffic flowing between port1 and port17 using the diagnose sniffer command.

Which two commands allow the administrator to view the traffic? (Choose two.)

A)

Question # 26

B)

Question # 26

C)

Question # 26

D)

Question # 26

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Questions # 27:

Exhibit.

Question # 27

Refer to the exhibit, which shows the output of get system ha status.

NGFW-1 and NGFW-2 have been up for a week.

Which two statements about the output are true? (Choose two.)

Options:

A.

If a configuration change is made to the primary FortiGate at this time, the secondary will initiate a synchronization reset.


B.

If port 7 becomes disconnected on the secondary, both FortiGate devices will elect itself as primary.


C.

If FGVM...649 is rebooted. FGVM...650 will become the primary and retain that role, even after FGVM...649 rejoins the cluster.


D.

If no action is taken, the primary FortiGate will leave the cluster because of the current sync status.


Expert Solution
Questions # 28:

In the SAML negotiation process, which section does the Identity Provider (IdP) provide the SAML attributes utilized in the authentication process to the Service Provider (SP)?

Options:

A.

SP Login dump


B.

Authentication Response


C.

Authentication Request


D.

Assertion dump


Expert Solution
Questions # 29:

Refer to the exhibit.

Question # 29

An IPsec VPN tunnel is dropping, as shown by the debug output.

Analyzing the debug output, what could be causing the tunnel to go down?

Options:

A.

Phase 2 drops but Phase 1 is up.


B.

Dead Peer Detection is not receiving its acknowledge packet.


C.

The tunnel drops during rekey negotiation.


D.

The tunnel drops after the timer expires.


Expert Solution
Questions # 30:

Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.

Question # 30

What happens to the session information if a routing change occurs that affects this session?

Options:

A.

Only the interface and gateway information for dev=7 will be removed.


B.

The session information will not change unless the current route has been removed from the routing table.


C.

The session will be flagged as dirty but no route lookups will be performed.


D.

Sessions involving port7 or port19 will not have their routing information flushed.


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions