Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Certified Solution Specialist FCSS_NST_SE-7.6 Questions and answers with CertsForce

Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which two statements about application-layer test commands are true? (Choose two answers)

Options:

A.

Some of them display statistics and configuration information about a feature or process.


B.

Some of them display real-time application debugs.


C.

Some of them display output only after you run the diagnose debug console enable command.


D.

Some of them can be used to restart an application.


Expert Solution
Questions # 32:

What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?

Options:

A.

A mismatched proposal was detected during the IKE_AUTH exchange.


B.

A mismatched Diffie-Hellman group was detected during the IKE_SA_INIT exchange.


C.

A mismatched pre-shared key was detected during the IKE_AUTH exchange.


D.

Mismatched quick-mode selectors were detected during the CREATE_CHILD_SA exchange.


Expert Solution
Questions # 33:

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Question # 33

The administrator does not have access to the remote gateway.

Based on the debug output, which configuration change the administrator make to the local gateway to resolve the phase 1 negotiation error?

Options:

A.

In the phase 1 proposal configuration, add AES256-SHA256 to the list of encryption algorithms.


B.

In the phase 1 proposal configuration, add AESCBC-SHA2 to the list of encryption algorithms.


C.

In the phase 1 network configuration, set the IKE version to 2.


D.

In the phase 1 proposal configuration, add AES128-SHA128 to the list of encryption algorithms.


Expert Solution
Questions # 34:

Refer to the exhibits.

Question # 34

An administrator is attempting to advertise the network configured on port3. However, FGT-A is not receiving the prefix.

Which two actions can the administrator take to fix this problem? (Choose two.)

Options:

A.

Modify the prefix using the network command from 172.16.0.0/16 to 172.16.54.0/24.


B.

Manually add the BGP route on FGT-A.


C.

Restart BGP using a soft reset to force both peers to exchange their complete BGP routing tables.


D.

Use the set network-import-check disable command.


Expert Solution
Questions # 35:

Which statement about parallel path processing is correct (PPP)?

Options:

A.

PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.


B.

Only FortiGate hardware configurations affect the path that a packet takes.


C.

PPP does not apply to packets that are part of an already established session.


D.

Software configuration has no impact on PPP.


Expert Solution
Questions # 36:

Refer to the exhibit.

Question # 36

Which route will traffic take to get to the 100.65.0.0/24 network considering the routes are all configured with the same distance?

Options:

A.

The BGP route


B.

The policy route


C.

The static route


D.

The OS PF route


Expert Solution
Questions # 37:

Refer to the exhibit.

Question # 37

The administrator did not override the FortiGuard FODN or IP address in the FortiGate configuration

Which IP address did FortiGate get when resolving the servicem,fortiguard.net name?

Options:

A.

208.91.112.194


B.

209.22.147.36


C.

64.26.151.37


D.

96.45.33.65


Expert Solution
Questions # 38:

Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.

Question # 38

What happens to the session information if a routing change occurs that affects this session?

Options:

A.

Only the interface and gateway information for dev=7 will be removed.


B.

The session information will not change unless the current route has been removed from the routing table.


C.

The session will be flagged as dirty but no route lookups will be performed.


D.

Sessions involving port7 or port19 will not have their routing information flushed.


Expert Solution
Questions # 39:

Refer to the exhibit, which shows the output of diagnose sys session list.

Question # 39

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

Options:

A.

The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.


B.

Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.


C.

The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.


D.

The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.


Expert Solution
Questions # 40:

Which authentication option can you not configure under config user radius on FortiOS?

Options:

A.

mschap


B.

pap


C.

mschap2


D.

eap


Expert Solution
Viewing page 4 out of 4 pages
Viewing questions 31-40 out of questions