Weekend Sale Special Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: CFsave75

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

Refer to the exhibit, which shows the output of the command get router info bgp neighbors 100.64.2.254 advertised-routes.

Question # 31

What can you conclude from the output?

Options:

A.

The BGP state of the two BGP participants is OpenConfirm.


B.

The router ID of the neighbor is 100.64.2.254.


C.

The BGP neighbor is advertising the 10.20.30.40/24 network to the local router.


D.

The local router is advertising the 10.20.30.40/24 network to its BGP neighbor.


Expert Solution
Questions # 32:

Consider the scenario where the server name indication (SNI) does not match either the common name (CN) or any of the subject alternative names (SAN) in the server certificate.

Which action will FortiGate take when using the default settings for SSL certificate inspection?

Options:

A.

FortiGate uses the SNI from the user ' s web browser.


B.

FortiGate closes the connection because this represents an invalid SSL/TLS configuration.


C.

FortiGate uses the first entry listed in the SAN field in the server certificate.


D.

FortiGate uses the CN information from the Subject field in the server certificate.


Expert Solution
Questions # 33:

Refer to the exhibit.

Question # 33

The routing table information is shown.

Assuming a default configuration, which three statements about the RPF check on FortiGate are

correct? (Choose three.)

Options:

A.

User C: Fail. There is no route to 10.0.4.63 using port1 in the routing table.


B.

User B: Pass. FortiGate will use asymmetric routing using want to reply to traffic for 95.56.234.24.


C.

User C: Pass. FortiGate will forward all incoming packets from User C using the default static route.


D.

User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table.


E.

User A: Pass. The default static route through want passes the RPF check regardless of the source IP address.


Expert Solution
Questions # 34:

Question # 34

The output of a policy route table entry is shown.

Which type of policy route does the output show?

Options:

A.

A regular policy route, which is not associated with an active static route in the FIB


B.

An ISDB route


C.

An SD-WAN rule


D.

A regular policy route, which is associated with an active static route in the FIB


Expert Solution
Questions # 35:

Which statement about protocol options is true?

Options:

A.

Protocol options allow administrators to configure a maximum number of sessions for each configured protocol.


B.

Protocol options give administrators a streamlined method to instruct FortiGate to block all sessions corresponding to disabled protocols.


C.

Protocol options allow administrators to configure the Any setting for all enabled protocols, which provides the most efficient use of system resources.


D.

Protocol options allow administrators to configure which Layer 4 port numbers map to upper-layer protocols, such as HTTP, SMTP, FTP, and so on.


Expert Solution
Questions # 36:

Refer to the exhibit, which shows the output of a diagnose command. What can you conclude from the RTT value?

Question # 36

Options:

A.

Its value represents the time it takes to receive a response after a rating request is sent to a particular server.


B.

Its value is incremented with each packet lost.


C.

It determines which FortiGuard server is used for license validation.


D.

Its initial value is statically set to 10.


Expert Solution
Questions # 37:

Exhibit.

Question # 37

Refer to the exhibit, which shows a partial output of diagnose hardware aysinfo memory.

Which two statements about the output are true? (Choose two.)

Options:

A.

There are 98908 kB of memory that will never be used.


B.

The user space has 708880 kB of physical memory that is not used by the system.


C.

The I/O cache, which has 641364 kB of memory allocated to it.


D.

The value indicated next to the inactive heading represents the currently unused cache page.


Expert Solution
Questions # 38:

Refer to the exhibit.

Question # 38

The output from a collector agent log is shown. The collector agent is showing the status of a workstation as Not Verified . What are two common causes for this message? (Choose two.)

Options:

A.

The workstation has come out of hibernate mode.


B.

The workstation remote registry service is not running.


C.

Traffic to ports 139 and 445 is blocked.


D.

DNS cannot resolve the workstation name.


Expert Solution
Questions # 39:

Refer to the exhibit.

Question # 39

The modified output of live routing kemel is shown

Which two statements about the output are (rue? (Choose two.)

Options:

A.

The BGP route to 10.0.4.0/24 is not in the forwarding information base.


B.

The default static route through 10.200.1 254 is in the forwarding information base.


C.

FortiGate is performing ECMP using both default static routes.


D.

The local FortiGate is receiving only one LSA from one OSPF neighbor.


Expert Solution
Questions # 40:

Refer to the exhibits.

Question # 40

The exhibits show the SD-WAN zone configuration of an SD-WAN template prepared on FortiManager and the policy package configuration.

When the administrator tries to install the configuration changes, FortiManager fails to commit.

What should the administrator do to fix the issue?

Options:

A.

Configure branch1_fgt as the installation target for policy 3.


B.

Configure HUB1 as the destination of policy 3.


C.

Configure a normalized interface for the IPsec tunnel HUB1-VPN1.


D.

Configure both HUB1-VPN1 and HUB1-VPN2 as the destination of policy 3.


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions