Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Fortinet NSE 7 Network Security Architect NSE7_FSN_AR-7.6 Questions and answers with CertsForce

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

Exhibit.

Question # 31

Refer to the exhibit, which shows the output of diagnose automation test.

What can you observe from the output? (Choose two.)

Options:

A.

The automation stitch test is not being logged.


B.

The automation stitch test failed but the HA failover was successful.


C.

An HA failover occurred.


D.

The test was unsuccessful.


Expert Solution
Questions # 32:

Which two protocol states indicate that traffic is bidirectional? (Choose two.)

Options:

A.

proto_state=01 for a TCP session.


B.

proto_state=01 for a UDP session.


C.

proto_state=05 for a TCP session.


D.

proto_state=00 for an ICMP session.


Expert Solution
Questions # 33:

Refer to the exhibit.

Question # 33

The partial output of a session table entry is shown.

Which two statements about the output shown in the exhibit are correct? (Choose two.)

Options:

A.

NP7 is handling offloading of this session.


B.

The traffic matches Policy ID 1.


C.

The session has been offloaded.


D.

The traffic is tagged for a VLAN interface.


Expert Solution
Questions # 34:

You want to harden the SSL/SSH inspection profile for access to HTTPS web servers.

Which two configuration changes allow you to remove vulnerabilities? (Choose two answers.)

Options:

A.

Set unsupported-ssl-version to block.


B.

Set Server certificate SNI check to Enable .


C.

Set Untrusted SSL certificates to Ignore .


D.

Set min-allowed-ssl-version to ssl-3.0.


Expert Solution
Questions # 35:

Refer to the exhibit, which shows the output of a policy route table entry.

Question # 35

Which type of policy route does the output show?

Options:

A.

An ISDB route


B.

A regular policy route


C.

A regular policy route, which is associated with an active static route in the FIB


D.

An SD-WAN rule


Expert Solution
Questions # 36:

Exhibit.

Question # 36

Refer to the exhibit, which shows a FortiGate configuration.

An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however the web filter is not inspecting any traffic that is passing through the policy.

What must the administrator do to fix the issue?

Options:

A.

Disable webfilter-force-off.


B.

Increase webfilter-timeout.


C.

Enable fortiguard-anycast.


D.

Change protocol to TCP.


Expert Solution
Questions # 37:

Refer to the exhibit, which shows the output of the command get router info bgp neighbors 100.64.2.254 advertised-routes.

Question # 37

What can you conclude from the output?

Options:

A.

The BGP state of the two BGP participants is OpenConfirm.


B.

The router ID of the neighbor is 100.64.2.254.


C.

The BGP neighbor is advertising the 10.20.30.40/24 network to the local router.


D.

The local router is advertising the 10.20.30.40/24 network to its BGP neighbor.


Expert Solution
Questions # 38:

Which two statements about Security Fabric communications are true? (Choose two.)

Options:

A.

By default, the downstream FortiGate establishes a connection with the upstream FortiGate using TCP port 8013.


B.

FortiTelemetry must be manually enabled on the FortiGate interface.


C.

The default ports for FortiTelemetry and Neighbor Discovery can be modified.


D.

Security Fabric communication is enabled by default among all Fortinet devices.


Expert Solution
Questions # 39:

Refer to the exhibit showing a debug output.

Question # 39

An administrator deployed FSSO in DC Agent Mode but FSSO is failing on FortiGate. Pinging FortiGate from where the collector agent is deployed is successful.

The administrator then produces the debug output shown in the exhibit.

What could be causing this error message?

Options:

A.

The TCP port 445 is blocked between FortiGate and collector agent.


B.

The collector agent preshared password is mismatched.


C.

The FortiGate cannot resolve the active directory server name.


D.

The FortiGate and the collector agent are using different TCP ports.


Expert Solution
Questions # 40:

Refer to the exhibit.

Question # 40

Partial output of command diagnose debug rating is shown. Which FDS server will the FortiGate algorithm choose?

Options:

A.

96.45.33.65


B.

208.91.112.194


C.

64.26.151.37


D.

209.22.147.36


Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions