Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet Fortinet Network Security Expert NSE7_CDS_AR-7.6 Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit.

Question # 11

An AWS administrator created a change set to examine the effects of proposed changes to the current infrastructure.

Based only on the output shown in the exhibit, what will happen if the administrator applies these changes?

Options:

A.

The resulting FortiGate instance will lose its current local users.


B.

The deployment will take place without any service interruption.


C.

The PhysicalResourceId will remain the same.


D.

CloudFormation will roll back the current stack before updating it.


Expert Solution
Questions # 12:

Refer to the exhibit.

Question # 12

You are troubleshooting a Microsoft Azure SDN connector issue on your FortiGate VM in Azure.

Which command can you use to examine details about API calls sent by the connector?

Options:

A.

diag debug application cloud-connector -1


B.

diag test application azd 1


C.

diag debug application azd -1


D.

get system sdn-connector


Expert Solution
Questions # 13:

Refer to the exhibit.

Question # 13

After the initial Terraform configuration in Microsoft Azure, the terraform plan command is run.

Which two statements about running the terraform plan command are true? (Choose two.)

Options:

A.

The terraform plan command will deploy the rest of the resources except the service principle details.


B.

You cannot run the terraform apply command before the terraform plan command.


C.

The terraform plan command makes terraform do a dry run.


D.

You must run the terraform init command once, before the terraform plan command.


Expert Solution
Questions # 14:

Refer to the exhibit.

Question # 14

An administrator installed a FortiWeb ingress controller to protect a containerized web application. What is the reason for the status shown in FortiView? (Choose one answer)

Options:

A.

The SDN connector is not authenticated correctly.


B.

The FortiWeb VM is missing a route to the node subnet.


C.

The manifest file deployed is configured with the wrong node IP addresses.


D.

The load balancing type is not set to round-robin.


Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

Your team notices an unusually high volume of traffic sourced at one of the organizations FortiGate EC2 instances. They create a flow log to obtain and analyze detailed information about this traffic. However, when they checked the log, they found that it included traffic that was not associated with the FortiGate instance in question.

What can they do to obtain the correct logs? (Choose one answer)

Options:

A.

Create a new flow log at the interface level.


B.

Change the maximum aggregation time to 1 minute.


C.

Ensure that the flow log data is not mixed with the rest of the traffic.


D.

Send the logs to Amazon Data Firehose instead to get more granular information.


Expert Solution
Questions # 16:

Which FortiCNAPP feature correlates findings into a single, contextualized view so that security teams can focus on addressing the most critical threats instead of chasing isolated alerts?

Options:

A.

Attack path


B.

SmartFix


C.

Composite alert


D.

Exposure polygraph


Expert Solution
Questions # 17:

Refer to the exhibit.

Question # 17

An administrator used the what-if tool to preview the changes to an Azure Bicep file. What will happen if the administrator applies these changes in Azure? (Choose one answer)

Options:

A.

A new subnet will be added to vnet-002.


B.

The vnet-002 VNet will be renamed Production.


C.

The resulting VNet will have a single subnet.


D.

The VNet address space will be updated.


Expert Solution
Questions # 18:

Refer to the exhibit.

Question # 18

You deployed a FortiGate HA active-passive cluster in Microsoft Azure.

Which two statements regarding this particular deployment are true? (Choose two.)

Options:

A.

You can use the vdom-exception command to synchronize the configuration.


B.

During a failover, all existing sessions are transferred to the new active FortiGate.


C.

The configuration does not synchronize between the primary and secondary devices.


D.

There is no SLA for API calls from Microsoft Azure.


Expert Solution
Questions # 19:

Which statement about Transit Gateway (TGW) in Amazon Web Services (AWS) is true?

Options:

A.

Both the TGW attachment and propagation must be in the same TGW route table.


B.

TGW can have multiple TGW route tables.


C.

A TGW attachment can be associated with multiple TGW route tables.


D.

The TGW default route table cannot be disabled.


Expert Solution
Questions # 20:

An administrator implements FortiWeb ingress controller to protect containerized web applications in an AWS Elastic Kubernetes Service (EKS) cluster.

Question # 20

What can you conclude about the topology shown in FortiView?

Options:

A.

The FortiWeb VM gets the latest cluster information through an SDN connector.


B.

This topology has two services and two ingress controllers deployed.


C.

Both services will be load balanced among the two nodes and the four pods.


D.

Adding a new service will update the FortiWeb configuration automatically.


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions