Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions
Questions # 1:

Refer to the exhibit.

Question # 1

A network topology and a partial routing table are shown.

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.

Which two changes can the administrator perform to ensure the server at 10.4.0.1/24 receives the ICMP echo reply from the laptop at 10.1.0.1/24? (Choose two.)

Options:

A.

Enable asymmetric routing under config system settings.


B.

Change the FortiGate configuration from strict RPF check mode to feasible RPF check mode.


C.

Modify the default gateway on the laptop from 10.1.0.2 to 10.1.0.254.


D.

Add a default static route on FortiGate to forward all traffic to port3.


Expert Solution
Questions # 2:

Refer to the exhibit, which shows a partial output of the real-time LDAP debug.

Question # 2

What two actions can the administrator take to resolve this issue? (Choose two.)

Options:

A.

Ensure the user logs in using ' John Smith ' not ' jsmith ' .


B.

Ensure the user is providing the correct user credentials.


C.

Ensure the user is a member of at least one AD group to ensure step 4 of the LDAP authentication process is successful.


D.

Ensure the account is active.


Expert Solution
Questions # 3:

Refer to the exhibit, which shows the output of diagnose sys session list.

Question # 3

If the HA ID for the primary device is 0, what happens if the primary fails and the secondary becomes the primary?

Options:

A.

The secondary device has this session synchronized; however, because application control is applied, the session is marked dirty and has to be re-evaluated after failover.


B.

Traffic for this session continues to be permitted on the new primary device after failover, without requiring the client to restart the session with the server.


C.

The session will be removed from the session table of the secondary device because of the presence of allowed error packets, which will force the client to restart the session with the server.


D.

The session state is preserved but the kernel will need to re-evaluate the session because NAT was applied.


Expert Solution
Questions # 4:

Which statement about IKEv2 is true?

Options:

A.

Both IKEv1 and IKEv2 share the feature of asymmetric authentication.


B.

IKEv1 and IKEv2 have enough of the header format in common that both versions can run over the same UDP port.


C.

IKEv1 and IKEv2 use the same TCP port but run on different UDP ports.


D.

IKEv1 and IKEv2 share the concept of phase1 and phase2.


Expert Solution
Questions # 5:

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate. Which two actions will FortiGate take when using the default settings for SSL certificate inspection? (Choose two answers)

Options:

A.

FortiGate uses the SNI from the user ' s web browser.


B.

FortiGate does not decrypt the traffic if the traffic is blocked by the web filter profile.


C.

FortiGate uses the CN information from the Subject field in the server certificate.


D.

FortiGate does not decrypt the traffic if the traffic is allowed by the web filter profile.


Expert Solution
Questions # 6:

Refer to the exhibit.

Question # 6

The output of the command diagnose vpn tunnel list is shown.

Reviewing the debug command, what is the current status of the traffic flowing through the tunnel?

Options:

A.

The outbound IPsec SA was copied to the NPU.


B.

NP6 is handling the offloading.


C.

The inbound and outbound IPsec SAs were copied to the NPU.


D.

The inbound IPsec SA was copied to the NPU.


Expert Solution
Questions # 7:

Refer to the exhibit.

Question # 7

The VDOM configuration on a FortiGate device is shown. You discover that web filtering stopped working in Core1 and Core2 after a maintenance window.

What are two reasons why web filtering stopped working? (Choose two answers.)

Options:

A.

The root VDOM does not have access to FortiManager in a closed network.


B.

The root VDOM does not have access to any valid public Fortinet Distribution Network (FDN) server.


C.

The Core1 and Core2 VDOMs must also be enabled as management VDOMs to receive FortiGuard updates.


D.

The root VDOM does not use a VDOM link to connect with the Core1 and Core2 VDOMs.


Expert Solution
Questions # 8:

Refer to the exhibit, which shows a partial output of a real-time LDAP debug.

Question # 8

What two conclusions can you draw from the output? (Choose two.)

Options:

A.

The user was found in the LDAP tree, whose root is TAC.ottawa.fortinet.com.


B.

FortiOS performs a bind to the LDAP server using the user ' s credentials.


C.

FortiOS collects the user group information.


D.

FortiOS is performing the second step (Search Request) in the LDAP authentication process.


Expert Solution
Questions # 9:

Refer to the exhibit.

Question # 9

If the default settings are m place, what can you conclude about the conserve mode shown in the exhibit?

Options:

A.

FortiGate is currently allowing new sessions that require flow-based content inspection and blocking sessions that require proxy-based content inspection


B.

FortiGate is currently allowing new sessions and will continue to allow sessions if memory increases another 6%.


C.

FortiGate is currently allowing now sessions that require flow-based or proxy-based content inspection, but is not performing inspection on those sessions.


D.

FortiGate is currently blocking all new sessions regardless of the content inspection requirements or configuration settings because of high memory use.


Expert Solution
Questions # 10:

Refer to the exhibit, which shows a truncated output of a real-time LDAP debug.

Question # 10

What two conclusions can you draw from the output? (Choose two.)

Options:

A.

The name of the configured LDAP server is Lab.


B.

The user is authenticating using CN=John Smith.


C.

FortiOS is able to locate the user in step 3 (Bind Request) of the LDAP authentication process.


D.

FortiOS is performing the second step (Search Request) in the LDAP authentication process.


Expert Solution
Viewing page 1 out of 5 pages
Viewing questions 1-10 out of questions