Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

Refer to the exhibit, which shows a session entry.

Question # 11

Which statement about this session is true?

Options:

A.

Return traffic to the initiator is sent to 10.1.0.1.


B.

Return traffic to the initiator is sent lo 10.200.1.254.


C.

It is an ICMP session from 10.1.10.10 to 10.200.1.1.


D.

It is an ICMP session from 10.1.10.1 to 10.200.5.1.


Expert Solution
Questions # 12:

Which Iwo actions does FortiGate take after an administrator enables the auxiliary session selling? (Choose two.)

Options:

A.

FortiGate only offloads auxiliary sessions.


B.

FortiGate accelerates all ECMP traffic to the NP6 processor


C.

FortiGates creates a now auxiliary session for each packet it receives.


D.

FortiGate creates two sessions in case of a routing change.


Expert Solution
Questions # 13:

Which three common FortiGate-to-collector-agent connectivity issues can you identify using the FSSO real-time debug? (Choose three.)

Options:

A.

Log is full on the collector agent.


B.

Inability to reach IP address of the collector agent.


C.

Refused connection. Potential mismatch of TCP port.


D.

Mismatched pre-shared password.


E.

Incompatible collector agent software version.


Expert Solution
Questions # 14:

Refer to the exhibit.

Question # 14

The exhibit shows the output of a session. Which two statements are correct? (Choose two.)

Options:

A.

The session did not match a firewall policy.


B.

The gateway to the destination is 10.1.10.1.


C.

The session was initiated from an authenticated user.


D.

The TCP session has been successfully established.


Expert Solution
Questions # 15:

Refer to the exhibit.

Question # 15

The output of the get router info bgp summary command is shown.

Which statement regarding adjacencies between the local router and its neighbors is correct?

Options:

A.

The local router and neighbor 100.64.2.254 are unable to establish adjacency until the adjacency with neighbor 100.64.1.254 ceases.


B.

The local router and neighbor 100.64.2.254 are unable to establish adjacency because the TCP session could not be established.


C.

The local router and neighbor 100.64.1.254 established adjacency because the priority of 100.64.1.254 is higher than that of 100.64.2.254.


D.

The local router and neighbor 100.64.2.254 are unable to establish adjacency because AS 100 is already used by neighbor 100.64.1.254.


Expert Solution
Questions # 16:

Refer to the exhibit.

Question # 16

A partial output from an IKE real-time debug is shown

The administrator does not have access to (he remote gateway

Based on the debug output, which two conclusions can you draw? (Choose two.)

Options:

A.

The remote peer is the initiating peer.


B.

This is a phase1 negotiation.


C.

There is a Diffie-Hellman group mismatch.


D.

This is a phase2 negotiation


Expert Solution
Questions # 17:

Refer to the exhibit, which shows the port1 interface configuration on FortiGate and partial session information for ICMP traffic.

Question # 17

What happens to the session information if a routing change occurs that affects this session?

Options:

A.

Only the interface and gateway information for dev=7 will be removed.


B.

The session information will not change unless the current route has been removed from the routing table.


C.

The session will be flagged as dirty but no route lookups will be performed.


D.

Sessions involving port7 or port19 will not have their routing information flushed.


Expert Solution
Questions # 18:

Which statement about parallel path processing is correct (PPP)?

Options:

A.

PPP chooses from a group of parallel options lo identity the optimal path tor processing a packet.


B.

Only FortiGate hardware configurations affect the path that a packet takes.


C.

PPP does not apply to packets that are part of an already established session.


D.

Software configuration has no impact on PPP.


Expert Solution
Questions # 19:

Refer to the exhibit, which a network topology and a partial routing table.

Question # 19

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.

Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?

Options:

A.

Enable asymmetric routing under config system settings.


B.

Change the configuration from strict RPF check mode to feasible RPF check mode.


C.

A firewall policy that allows all ICMP traffic from port3 to port1.


D.

Modify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.


Expert Solution
Questions # 20:

Refer to the exhibit.

Partial output of a real-time OSPF debug is shown.

Question # 20

Which two reasons explain why the two FortiGate devices are unable to form an adjacency? (Choose two.)

Options:

A.

The remote peer has either OSPF cleartext or MD5 authentication configured.


B.

There is an OSPF authentication configuration mismatch.


C.

The local FortiGate does not have OSPF authentication configured


D.

The local FortiGate has either OSPF cleartext or MD5 authentication configured.


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions