Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit, which shows partial outputs from two routing debug commands.

Question # 11

Why is the port2 default route not in the second command output?

Options:

A.

The port2 interface is disabled in the FortiGate configuration.


B.

The port1 default route has a higher priority value than the default route using port2.


C.

The port1 default route has a lower priority value than the default route using port2.


D.

The port1 default route has a lower distance than the default route using port2.


Expert Solution
Questions # 12:

Refer to the exhibit, which shows the output of get router info bgp summary.

Question # 12

Which two statements are true? (Choose two.)

Options:

A.

The local ForliGate has received one prefix from BGP neighbor 100.64.1.254.


B.

The TCP connection with BGP neighbor 100.64.2.254 was successful.


C.

The local FortiGate has received 18 packets from a BGP neighbor.


D.

The local FortiGate is still calculating the prefixes received from BGP neighbor 100.64.2.264


Expert Solution
Questions # 13:

In a Security Fabric environment which three actions must you take to ensure successful communication among the nodes? (Choose three.)

Options:

A.

You must ensure that TCP port 8013 is not blocked along the way.


B.

You must ensure that the port for Neighbor Discovery has been changed.


C.

You must configure FortiGate in transparent mode.


D.

You must authorize the downstream FortiGate on the root FortiGate.


E.

You must enable FortiTelemetry on the receiving interlace of the upstream FortiGate.


Expert Solution
Questions # 14:

While troubleshooting a FortiGate web filter issue, users report that they cannot access any websites, even though those sites are not explicitly blocked by any web filter profiles that are applied to firewall policies.

Question # 14

What are the three most likely reasons for this behavior? (Choose three answers)

Options:

A.

The web filter cache has been cleared causing all websites to take longer to be rated.


B.

The SSL/TLS deep inspection was configured but the browsers do not have the FortiGate certificate installed.


C.

The webfilter-force-off setting has been enabled under config system fortiguard.


D.

The DNS server is unreachable, preventing URL resolution.


E.

The FortiGuard Web Filtering license has expired, causing FortiGate to apply the default block action.


Expert Solution
Questions # 15:

Which two statements are true regarding heartbeat messages sent from an FSSO collector agent to FortiGate? (Choose two.)

Options:

A.

The heartbeat messages can be seen using the command diagnose debug authd fsso list.


B.

The heartbeat messages can be seen in the collector agent logs.


C.

The heartbeat messages can be seen on FortiGate using the real-lime FSSO debug.


D.

The heartbeat messages must be manually enabled on FortiGate.


Expert Solution
Questions # 16:

Refer to the exhibit, which contains the output of diagnose vpn tunnel list.

Question # 16

Which command will capture ESP traffic for the VPN named DialUp_0?

Options:

A.

diagnose sniffer packet any ' ip proto 50 '


B.

diagnose sniffer packet any ' host 10.0.10.10 '


C.

diagnose sniffer packet any ' esp and host 10.200.3.2 '


D.

diagnose sniffer packet any ' port 4500 '


Expert Solution
Questions # 17:

Refer to the exhibit.

Question # 17

The partial output of FortiOS kernel slabs is shown. Which statement about total slab size is true?

Options:

A.

The total slab size of the ip_session Tlab is 14080 kB and is associated with the user space.


B.

The total slab size of the tcp_session slab is 7500 kB and is associated with the kernel.


C.

The total slab size of the ip6_session slab is 1472 kB and is associated with the kernel.


D.

The total slab size of the UDPv6 slab is 14080 kB and is associated with the user space.


Expert Solution
Questions # 18:

What can cause an IKEv2 tunnel to go down after it was initially brought up successfully?

Options:

A.

A mismatched proposal was detected during the IKE_AUTH exchange.


B.

A mismatched Diffie-Hellman group was detected during the IKE_SA_INIT exchange.


C.

A mismatched pre-shared key was detected during the IKE_AUTH exchange.


D.

Mismatched quick-mode selectors were detected during the CREATE_CHILD_SA exchange.


Expert Solution
Questions # 19:

In IKEv2, which exchange establishes the first CHILD_SA?

Options:

A.

IKE_SA_INIT


B.

INFORMATIONAL


C.

CREATE_CHILD_SA


D.

IKE_AUTH


Expert Solution
Questions # 20:

Refer to the exhibit.

Question # 20

An IPsec VPN tunnel using IKEv2 was brought up successfully, but when the tunnel rekey takes place the tunnel goes down.

The debug command for IKE was enabled and, in the exhibit, you can review the partial output of the debug IKE while attempting to bring the tunnel up.

What is causing. The tunnel to be down?

Options:

A.

A Diffie-Hellman mismatch


B.

Blocked traffic on UDP port 500


C.

A mismatch m the Phase 1 negotiations


D.

A mismatch in the Phase 2 negotiations


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions