Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Refer to the exhibit.

The output of a BGO debug command is shown.

Question # 21

What is the most likely reason that the local FortiGate is not receiving any prefixes from its neighbors?

Options:

A.

The local router is waiting for the keepalive message from the router 10.125.0.60.


B.

None of the three neighbors has successfully established the TCP three-way handshake with the local router.


C.

The router 100.64.3.1 is waiting for the OPEN message from the local router.


D.

The RIB-OUT configuration for router 10.127.0.75 prevents any route advertisement to the local router.


Expert Solution
Questions # 22:

Refer to the exhibit, which shows a partial web filter profile configuration.

Question # 22

The URL www.dropbox.com is categorized as File Sharing and Storage.

Which action does FortiGate take if a user attempts to access www.dropbox.com?

Options:

A.

FortiGate blocks the connection as an invalid URL.


B.

Based on the URL Filter configuration, FortiGate allows the connection.


C.

FortiGate blocks the connection, based on the FortiGuard category-based filter configuration.


D.

Based on the Web Content filter configuration, access to www.dropbox.com would be exempted.


Expert Solution
Questions # 23:

Which two statements about application-layer test commands are true? (Choose two answers)

Options:

A.

Some of them display statistics and configuration information about a feature or process.


B.

Some of them display real-time application debugs.


C.

Some of them display output only after you run the diagnose debug console enable command.


D.

Some of them can be used to restart an application.


Expert Solution
Questions # 24:

Exhibit 1.

Question # 24

Exhibit 2.

Question # 24

Refer to the exhibits, which show the configuration on FortiGate and partial internet session information from a user on the internal network.

An administrator would like to lest session failover between the two service provider connections.

Which two changes must the administrator make to force this existing session to immediately start using the other interface? (Choose two.)

Options:

A.

Change the priority of the port1 static route to 11.


B.

Change the priority of the port2 static route to 5.


C.

Configure unset snat-route-change to return it to the default setting.


D.

Configure set snat-route-change enable.


Expert Solution
Questions # 25:

Refer to the exhibit.

Question # 25

You want to configure SD-WAN on a network, as shown in the exhibit. The network contains many FortiGate devices. Some are used as next-generation firewalls (NGFWs), and some are deployed with extensions such as FortiSwitch, FortiAP, or FortiExtender.

Which factor should you consider when planning the deployment? (Choose one answer.)

Options:

A.

You can build an SD-WAN topology that includes all devices. The hubs must be devices without extensions.


B.

You should exclude FortiGate devices with FortiLink connections from the SD-WAN topology.


C.

You should build multiple SD-WAN topologies. Each topology should contain only one type of extension.


D.

You can build an SD-WAN topology that includes all devices. The hubs can be FortiGate devices with FortiExtender.


Expert Solution
Questions # 26:

Exhibit.

Question # 26

Refer to the exhibit, which contains partial output from an IKE real-time debug.

Which two statements about this debug output are correct? (Choose two.)

Options:

A.

Perfect Forward Secrecy (PFS) is enabled in the configuration.


B.

The local gateway IP address is 10.0.0.1.


C.

It shows a phase 2 negotiation.


D.

The initiator provided remote as its IPsec peer ID.


Expert Solution
Questions # 27:

An administrator wants to capture encrypted phase 2 traffic between two FotiGate devices using the built-in sniffer.

If the administrator knows that there Is no NAT device located between both FortiGate devices, which command should the administrator run?

Options:

A.

diagnose sniffer packet any ' udp port 500 '


B.

diagnose sniffer packet any ' lp proto 50 '


C.

diagnose sniffer packet any ' udp port 4500 '


D.

diagnose sniffer packet any ' ah '


Expert Solution
Questions # 28:

Refer to the exhibit.

Question # 28

The output of the get router info bgp summary command is shown.

Which statement regarding adjacencies between the local router and its neighbors is correct?

Options:

A.

The local router and neighbor 100.64.2.254 are unable to establish adjacency until the adjacency with neighbor 100.64.1.254 ceases.


B.

The local router and neighbor 100.64.2.254 are unable to establish adjacency because the TCP session could not be established.


C.

The local router and neighbor 100.64.1.254 established adjacency because the priority of 100.64.1.254 is higher than that of 100.64.2.254.


D.

The local router and neighbor 100.64.2.254 are unable to establish adjacency because AS 100 is already used by neighbor 100.64.1.254.


Expert Solution
Questions # 29:

In which two slates is a given session categorized as ephemeral? (Choose two.)

Options:

A.

A UDP session with only one packet received


B.

A UOP session with packets sent and received


C.

A TCP session waiting for the SYN ACK


D.

A TCP session waiting for FIN ACK


Expert Solution
Questions # 30:

Refer to the exhibit.

Question # 30

A partial output of diagnose npu up6 port-list on FortiGate 2000E is shown.

An administrator is unable to analyze traffic flowing between port1 and port17 using the diagnose sniffer command.

Which two commands allow the administrator to view the traffic? (Choose two.)

A)

Question # 30

B)

Question # 30

C)

Question # 30

D)

Question # 30

Options:

A.

Option A


B.

Option B


C.

Option C


D.

Option D


Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions